|
|
Log in / Subscribe / Register

Arch Linux alert ASA-201709-17 (tomcat7)

From:  Levente Polyak <anthraxx@archlinux.org>
To:  arch-security@archlinux.org
Subject:  [arch-security] [ASA-201709-17] tomcat7: information disclosure
Date:  Thu, 21 Sep 2017 15:01:48 +0200
Message-ID:  <1957df20-1e8f-c1f4-6352-1caa5d6bad5c@archlinux.org>

Arch Linux Security Advisory ASA-201709-17 ========================================== Severity: Medium Date : 2017-09-19 CVE-ID : CVE-2017-12616 Package : tomcat7 Type : information disclosure Remote : Yes Link : https://security.archlinux.org/AVG-408 Summary ======= The package tomcat7 before version 7.0.81-1 is vulnerable to information disclosure. Resolution ========== Upgrade to 7.0.81-1. # pacman -Syu "tomcat7>=7.0.81-1" The problem has been fixed upstream in version 7.0.81. Workaround ========== None. Description =========== It has been discovered that tomcat version 7.0.80 and before are vulnerable to information disclosure. When using a VirtualDirContext it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request. Impact ====== A remote attacker is able to view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request. References ========== http://tomcat.apache.org/security-7.html#Fixed_in_Apache_... https://mail-archives.apache.org/mod_mbox/tomcat-announce... http://svn.apache.org/viewvc?view=revision&revision=1... https://security.archlinux.org/CVE-2017-12616


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds