The previous fix for Tomcat vulnerability CVE-2007-3385 was incomplete. It did not consider the use of quotes or %5C within a cookie value.

http://www.securiteam.com/unixfocus/5AP0E00NFW.html