Oval Definition:oval:org.cisecurity:def:1624
Revision Date:2017-01-13Version:6
Title:DLA-729-1 -- tomcat7 security update
Description:Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, which may result in possible timing attacks to determine valid user names, bypass of the SecurityManager, disclosure of system properties, unrestricted access to global resources, arbitrary file overwrites, and potentially escalation of privileges. In addition this update further hardens Tomcat's init and maintainer scripts to prevent possible privilege escalations.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2016-0762
CVE-2016-5018
CVE-2016-6794
CVE-2016-6796
CVE-2016-6797
CVE-2016-6816
CVE-2016-8735
DLA-729-1
Platform(s):Debian GNU/kFreeBSD 7
Debian GNU/Linux 7
Product(s):tomcat7
Definition Synopsis
  • Debian 7 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND tomcat7 is earlier than 0:7.0.28-4+deb7u7
  • BACK