Ubuntu alert USN-8383-1 (tomcat6, tomcat7)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8383-1] Tomcat vulnerabilities | |
| Date: | Fri, 05 Jun 2026 07:34:11 +0000 | |
| Message-ID: | <E1wVP4F-0002BB-O2@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8383-1 June 04, 2026 tomcat6, tomcat7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Tomcat. Software Description: - tomcat7: Servlet and JSP engine - tomcat6: Servlet and JSP engine Details: It was discovered that Tomcat incorrectly handled digest authentication. A remote attacker could possibly use this issue to bypass authentication restrictions. (CVE-2026-43512) It was discovered that Tomcat incorrectly handled case sensitivity in LockOutRealm. A remote attacker could possibly use this issue to bypass account lockout protections and obtain sensitive information. (CVE-2026-43513) It was discovered that Tomcat incorrectly handled authorization when multiple method constraints defined the same HTTP method. A remote attacker could possibly use this issue to bypass authorization restrictions. (CVE-2026-43515) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libtomcat7-java 7.0.68-1ubuntu0.4+esm4 Available with Ubuntu Pro tomcat7 7.0.68-1ubuntu0.4+esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS libtomcat6-java 6.0.39-1ubuntu0.1+esm3 Available with Ubuntu Pro libtomcat7-java 7.0.52-1ubuntu0.16+esm2 Available with Ubuntu Pro tomcat6 6.0.39-1ubuntu0.1+esm3 Available with Ubuntu Pro tomcat7 7.0.52-1ubuntu0.16+esm2 Available with Ubuntu Pro After a standard system update you need to restart Tomcat to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8383-1 CVE-2026-43512, CVE-2026-43513, CVE-2026-43515
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmohfgIACgkQcpJm3tlz hgGYHhAAtRRBrQ40DV+th6FUeMbYvtAHI6ZM9Q3pPp6xREogLs4LrHg9BefxLr1E pJtRxSZboeF8tTt8+5ksT5Gh6yHc0RMr3PS791lifh2jqtU36CMhMJmrpc2URTNk GpiErzNNIIK9HO1dp+yYCv6ixHSWa54nkHYv7N4yaYHzUn2NMyDcSbiHhpR3Er+b f91ioMovGF8FFyIbgonafqvl0uS4O4B9/sCp9ZlCcGB0VsqLltEHyw8/PRZxUYIY fLZU0jftIycTg3Qg7sTneKO0LEI1Yf7WoNaaERFPvWZ7Ehkwv2bSls1gy1uCvtzN crHNQ4y8umTl5sxxugFnKqVGsxURdtgjnKo14BTR922MLdV4+x17EBniHxu/GDl8 kecHJO+Ze91I3Ch0oWECULCIMD9wAmm7xGUrHjzn1MGnCRRvgFZMlHsuzN2rNdz3 nQgF2diSe1lu2SIS5ckmBzlaECYer5c/M77XELN+PTKWgIOJxTYoUFwepb/tHmzp Yy1qSraPLhKVguSpeQjdIgtNgeBciC/r/coVyUnf+IE0pEiWYt62mP/2iYreQSWi C2P+Fod+5Hi234XD4F5ooQNXfxVVF75aDH2cTKem8oHbq+UhMmXeL0Z6r7rvfO9P 8YiVWZKIrs6jWkmiDvR08PEvNrXVmwLzh29xkmff7bGJS08N/Dw= =5u+p -----END PGP SIGNATURE-----
