|
|
| |
|
| |
tomcat: multiple vulnerabilities
| Package(s): | tomcat6 |
CVE #(s): | CVE-2012-2733
CVE-2012-5885
CVE-2012-5886
CVE-2012-5887
CVE-2012-3439
|
| Created: | November 22, 2012 |
Updated: | January 10, 2013 |
| Description: |
From the Ubuntu advisory:
It was discovered that the Apache Tomcat HTTP NIO connector incorrectly
handled header data. A remote attacker could cause a denial of service by
sending requests with a large amount of header data. (CVE-2012-2733)
It was discovered that Apache Tomcat incorrectly handled DIGEST
authentication. A remote attacker could possibly use these flaws to perform
a replay attack and bypass authentication. (CVE-2012-5885, CVE-2012-5886,
CVE-2012-5887) |
| Alerts: |
|
( Log in to post comments)
|
|
|