Oval Definition:oval:org.mitre.oval:def:12894
Revision Date:2014-06-23Version:20
Title:DSA-2160-1 tomcat6 -- several
Description:Several vulnerabilities were discovered in the Tomcat Servlet and JSP engine: CVE-2010-3718 It was discovered that the SecurityManager insufficiently restricted the working directory. CVE-2011-0013 It was discovered that the HTML manager interface is affected by cross-site scripting. CVE-2011-0534 It was discovered that NIO connector performs insufficient validation of the HTTP headers, which could lead to denial of service. The oldstable distribution is not affected by these issues.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2010-3718
CVE-2011-0013
CVE-2011-0534
DSA-2160-1
Platform(s):Debian GNU/kFreeBSD 6.0
Debian GNU/Linux 6.0
Product(s):tomcat6
Definition Synopsis
  • Debian 6.0 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND Installed architecture is all
  • AND tomcat6 DPKG is earlier than 6.0.28-9+squeeze1
  • BACK