LWN.net Logo

tomcat: multiple vulnerabilities

Package(s):tomcat6, tomcat7 CVE #(s):CVE-2012-3544 CVE-2013-2067
Created:May 29, 2013 Updated:August 7, 2013
Description: From the Ubuntu advisory:

It was discovered that Tomcat incorrectly handled certain requests submitted using chunked transfer encoding. A remote attacker could use this flaw to cause the Tomcat server to stop responding, resulting in a denial of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS. (CVE-2012-3544)

It was discovered that Tomcat incorrectly handled certain authentication requests. A remote attacker could possibly use this flaw to inject a request that would get executed with a victim's credentials. This issue only affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS, and Ubuntu 12.10. (CVE-2013-2067)

Alerts:
Ubuntu USN-1841-1 2013-05-28
Red Hat RHSA-2013:0964-01 2013-06-20
CentOS CESA-2013:0964 2013-06-20
Oracle ELSA-2013-0964 2013-06-20
Scientific Linux SL-tomc-20130620 2013-06-20
Debian DSA-2725-1 2013-07-18
openSUSE openSUSE-SU-2013:1307-1 2013-08-07
openSUSE openSUSE-SU-2013:1411-1 2013-09-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds