Lucene search

K
ubuntuUbuntuUSN-1841-1
HistoryMay 28, 2013 - 12:00 a.m.

Tomcat vulnerabilities

2013-05-2800:00:00
ubuntu.com
34

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

High

0.718 High

EPSS

Percentile

98.1%

Releases

  • Ubuntu 13.04
  • Ubuntu 12.10
  • Ubuntu 12.04
  • Ubuntu 10.04

Packages

  • tomcat6 - Servlet and JSP engine
  • tomcat7 - Servlet and JSP engine

Details

It was discovered that Tomcat incorrectly handled certain requests
submitted using chunked transfer encoding. A remote attacker could use this
flaw to cause the Tomcat server to stop responding, resulting in a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2012-3544)

It was discovered that Tomcat incorrectly handled certain authentication
requests. A remote attacker could possibly use this flaw to inject a
request that would get executed with a victim’s credentials. This issue
only affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS, and Ubuntu 12.10.
(CVE-2013-2067)

It was discovered that Tomcat sometimes exposed elements of a previous
request to the current request. This could allow a remote attacker to
possibly obtain sensitive information. This issue only affected Ubuntu
12.10 and Ubuntu 13.04. (CVE-2013-2071)

OSVersionArchitecturePackageVersionFilename
Ubuntu13.04noarchlibtomcat7-java< 7.0.35-1~exp2ubuntu1.1UNKNOWN
Ubuntu13.04noarchlibservlet3.0-java< 7.0.35-1~exp2ubuntu1.1UNKNOWN
Ubuntu13.04noarchlibservlet3.0-java-doc< 7.0.35-1~exp2ubuntu1.1UNKNOWN
Ubuntu13.04noarchtomcat7< 7.0.35-1~exp2ubuntu1.1UNKNOWN
Ubuntu13.04noarchtomcat7-admin< 7.0.35-1~exp2ubuntu1.1UNKNOWN
Ubuntu13.04noarchtomcat7-common< 7.0.35-1~exp2ubuntu1.1UNKNOWN
Ubuntu13.04noarchtomcat7-docs< 7.0.35-1~exp2ubuntu1.1UNKNOWN
Ubuntu13.04noarchtomcat7-examples< 7.0.35-1~exp2ubuntu1.1UNKNOWN
Ubuntu13.04noarchtomcat7-user< 7.0.35-1~exp2ubuntu1.1UNKNOWN
Ubuntu12.10noarchlibtomcat7-java< 7.0.30-0ubuntu1.2UNKNOWN
Rows per page:
1-10 of 371

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

High

0.718 High

EPSS

Percentile

98.1%