Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-3375
HistoryJan 18, 2012 - 12:00 a.m.

CVE-2011-3375

2012-01-1800:00:00
ubuntu.com
ubuntu.com
16

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

0.003 Low

EPSS

Percentile

65.2%

Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly
perform certain caching and recycling operations involving request objects,
which allows remote attackers to obtain unintended read access to IP
address and HTTP header information in opportunistic circumstances by
reading TCP data.

Bugs

Notes

Author Note
mdeslaur advisory says Tomcat 6.0.30 to 6.0.33
OSVersionArchitecturePackageVersionFilename
ubuntu11.10noarchtomcat6<ย 6.0.32-5ubuntu1.2UNKNOWN
ubuntu11.10noarchtomcat7<ย 7.0.21-1ubuntu0.1UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

0.003 Low

EPSS

Percentile

65.2%