LWN.net Logo

tomcat: multiple vulnerabilities

Package(s):tomcat6 CVE #(s):CVE-2011-3375 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 CVE-2012-0022
Created:February 2, 2012 Updated:May 30, 2012
Description:

From the Debian advisory:

CVE-2011-3375: Incorrect request caching could lead to information disclosure.

CVE-2011-5062 CVE-2011-5063 CVE-2011-5064: The HTTP Digest Access Authentication implementation performed insufficient countermeasures against replay attacks.

CVE-2012-0022: This update adds countermeasures against a collision denial of service vulnerability in the Java hashtable implementation and addresses denial of service potentials when processing large amounts of requests.

Alerts:
Debian DSA-2401-1 2012-02-02
SUSE SUSE-SU-2012:0155-1 2012-02-07
openSUSE openSUSE-SU-2012:0208-1 2012-02-09
Ubuntu USN-1359-1 2012-02-13
Red Hat RHSA-2012:0474-01 2012-04-11
Red Hat RHSA-2012:0475-01 2012-04-11
CentOS CESA-2012:0474 2012-04-11
CentOS CESA-2012:0475 2012-04-11
Scientific Linux SL-tomc-20120411 2012-04-11
Scientific Linux SL-tomc-20120411 2012-04-11
Oracle ELSA-2012-0475 2012-04-12
Oracle ELSA-2012-0474 2012-04-12
Mandriva MDVSA-2012:085 2012-05-30
Gentoo 201206-24 2012-06-24
Mageia MGASA-2012-0189 2012-08-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds