LWN.net Logo

tomcat6: information leak

Package(s):tomcat6 CVE #(s):CVE-2011-2204 CVE-2011-2526
Created:September 2, 2011 Updated:February 2, 2012
Description: From the CVE entries:

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file. (CVE-2011-2204)

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web application. (CVE-2011-2526)

Alerts:
CentOS CESA-2011:1780 2011-12-22
CentOS CESA-2011:1845 2011-12-20
Oracle ELSA-2011-1845 2011-12-20
Scientific Linux SL-tomc-20111220 2011-12-20
Red Hat RHSA-2011:1845-01 2011-12-20
Scientific Linux SL-tomc-20111205 2011-12-05
Oracle ELSA-2011-1780 2011-12-05
Red Hat RHSA-2011:1780-01 2011-12-05
Ubuntu USN-1252-1 2011-11-08
Fedora FEDORA-2011-13456 2011-09-29
Fedora FEDORA-2011-13457 2011-09-29
Mandriva MDVSA-2011:156 2011-10-18
openSUSE openSUSE-SU-2011:0988-1 2011-09-02
Debian DSA-2401-1 2012-02-02
Oracle ELSA-2012-0474 2012-04-12

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds