LWN.net Logo

tomcat: information disclosure

Package(s):tomcat CVE #(s):CVE-2010-1157
Created:September 22, 2010 Updated:February 14, 2011
Description:

From the Novell report:

Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.

Alerts:
Pardus 2011-38 2011-02-14
openSUSE openSUSE-SU-2010:0616-1 2010-09-16
Gentoo 201206-24 2012-06-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds