Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 201206-24 ] Apache Tomcat: Multiple vulnerabilities
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Advocate
Advocate


Joined: 12 May 2004
Posts: 2663

PostPosted: Sun Jun 24, 2012 3:26 pm    Post subject: [ GLSA 201206-24 ] Apache Tomcat: Multiple vulnerabilities Reply with quote

Gentoo Linux Security Advisory

Title: Apache Tomcat: Multiple vulnerabilities (GLSA 201206-24)
Severity: normal
Exploitable: local, remote
Date: June 24, 2012
Bug(s): #272566, #273662, #303719, #320963, #329937, #373987, #374619, #382043, #386213, #396401, #399227
ID: 201206-24

Synopsis

Multiple vulnerabilities were found in Apache Tomcat, the worst of
which allowing to read, modify and overwrite arbitrary files.


Background

Apache Tomcat is a Servlet-3.0/JSP-2.2 Container.

Affected Packages

Package: www-servers/tomcat
Vulnerable: > 5.5.34 < 5.5.34
Vulnerable: > 6.0.35 < 6.0.35
Vulnerable: < 7.0.23
Unaffected: >= 6.0.35 < 6.0.36
Unaffected: >= 7.0.23
Architectures: All supported architectures


Description

Multiple vulnerabilities have been discovered in Apache Tomcat. Please
review the CVE identifiers referenced below for details.


Impact

The vulnerabilities allow an attacker to cause a Denial of Service, to
hijack a session, to bypass authentication, to inject webscript, to
enumerate valid usernames, to read, modify and overwrite arbitrary files,
to bypass intended access restrictions, to delete work-directory files,
to discover the server's hostname or IP, to bypass read permissions for
files or HTTP headers, to read or write files outside of the intended
working directory, and to obtain sensitive information by reading a log
file.


Workaround

There is no known workaround at this time.

Resolution

All Apache Tomcat 6.0.x users should upgrade to the latest version:
Code:
# emerge --sync
      # emerge --ask --oneshot --verbose ">=www-servers/tomcat-6.0.35"
   
All Apache Tomcat 7.0.x users should upgrade to the latest version:
Code:
# emerge --sync
      # emerge --ask --oneshot --verbose ">=www-servers/tomcat-7.0.23"
   


References

CVE-2008-5515
CVE-2009-0033
CVE-2009-0580
CVE-2009-0781
CVE-2009-0783
CVE-2009-2693
CVE-2009-2901
CVE-2009-2902
CVE-2010-1157
CVE-2010-2227
CVE-2010-3718
CVE-2010-4172
CVE-2010-4312
CVE-2011-0013
CVE-2011-0534
CVE-2011-1088
CVE-2011-1183
CVE-2011-1184
CVE-2011-1419
CVE-2011-1475
CVE-2011-1582
CVE-2011-2204
CVE-2011-2481
CVE-2011-2526
CVE-2011-2729
CVE-2011-3190
CVE-2011-3375
CVE-2011-4858
CVE-2011-5062
CVE-2011-5063
CVE-2011-5064
CVE-2012-0022
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum