LWN.net Logo

tomcat: multiple vulnerabilities

Package(s):tomcat6 CVE #(s):CVE-2012-2733 CVE-2012-5885 CVE-2012-5886 CVE-2012-5887 CVE-2012-3439
Created:November 22, 2012 Updated:January 10, 2013
Description:

From the Ubuntu advisory:

It was discovered that the Apache Tomcat HTTP NIO connector incorrectly handled header data. A remote attacker could cause a denial of service by sending requests with a large amount of header data. (CVE-2012-2733)

It was discovered that Apache Tomcat incorrectly handled DIGEST authentication. A remote attacker could possibly use these flaws to perform a replay attack and bypass authentication. (CVE-2012-5885, CVE-2012-5886, CVE-2012-5887)

Alerts:
Ubuntu USN-1637-1 2012-11-21
Fedora FEDORA-2012-20151 2012-12-19
openSUSE openSUSE-SU-2012:1701-1 2012-12-27
openSUSE openSUSE-SU-2012:1700-1 2012-12-27
Mandriva MDVSA-2013:004 2013-01-10
Mageia MGASA-2013-0015 2013-01-18
openSUSE openSUSE-SU-2013:0147-1 2013-01-23
Red Hat RHSA-2013:0623-01 2013-03-11
CentOS CESA-2013:0623 2013-03-12
Oracle ELSA-2013-0623 2013-03-11
Scientific Linux SL-tomc-20130312 2013-03-12
Red Hat RHSA-2013:0640-01 2013-03-12
CentOS CESA-2013:0640 2013-03-12
Oracle ELSA-2013-0640 2013-03-13
Scientific Linux SL-tomc-20130312 2013-03-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds