Oval Definition:oval:org.mitre.oval:def:13802
Revision Date:2014-06-30Version:20
Title:USN-1097-1 -- tomcat6 vulnerabilities
Description:It was discovered that the Tomcat SecurityManager did not properly restrict the working directory. An attacker could use this flaw to read or write files outside of the intended working directory. It was discovered that Tomcat did not properly escape certain parameters in the Manager application which could result in browsers becoming vulnerable to cross-site scripting attacks when processing the output. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain. It was discovered that Tomcat incorrectly enforced the maxHttpHeaderSize limit in certain configurations. A remote attacker could use this flaw to cause Tomcat to consume all available memory, resulting in a denial of service
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2010-3718
CVE-2011-0013
CVE-2011-0534
USN-1097-1
USN-1097-1
Platform(s):Ubuntu 10.04
Ubuntu 10.10
Ubuntu 9.10
Product(s):tomcat6
Definition Synopsis
  • Release section
  • Ubuntu 10.10 is installed
  • AND Installed architecture is all
  • AND Packages section
  • libservlet2.5-java DPKG is earlier than 6.0.28-2ubuntu1.2
  • OR libtomcat6-java DPKG is earlier than 6.0.28-2ubuntu1.2
  • OR tomcat6-docs DPKG is earlier than 6.0.28-2ubuntu1.2
  • OR libservlet2.5-java-doc DPKG is earlier than 6.0.28-2ubuntu1.2
  • OR tomcat6 DPKG is earlier than 6.0.28-2ubuntu1.2
  • OR tomcat6-admin DPKG is earlier than 6.0.28-2ubuntu1.2
  • OR tomcat6-common DPKG is earlier than 6.0.28-2ubuntu1.2
  • OR tomcat6-user DPKG is earlier than 6.0.28-2ubuntu1.2
  • OR tomcat6-examples DPKG is earlier than 6.0.28-2ubuntu1.2
  • OR Release section
  • Ubuntu 9.10 is installed
  • AND Installed architecture is all
  • AND Packages section
  • libservlet2.5-java DPKG is earlier than 6.0.20-2ubuntu2.4
  • OR libtomcat6-java DPKG is earlier than 6.0.20-2ubuntu2.4
  • OR tomcat6-docs DPKG is earlier than 6.0.20-2ubuntu2.4
  • OR libservlet2.5-java-doc DPKG is earlier than 6.0.20-2ubuntu2.4
  • OR tomcat6 DPKG is earlier than 6.0.20-2ubuntu2.4
  • OR tomcat6-admin DPKG is earlier than 6.0.20-2ubuntu2.4
  • OR tomcat6-common DPKG is earlier than 6.0.20-2ubuntu2.4
  • OR tomcat6-user DPKG is earlier than 6.0.20-2ubuntu2.4
  • OR tomcat6-examples DPKG is earlier than 6.0.20-2ubuntu2.4
  • OR Release section
  • Ubuntu 10.04 is installed
  • AND Installed architecture is all
  • AND Packages section
  • libservlet2.5-java DPKG is earlier than 6.0.24-2ubuntu1.7
  • OR libtomcat6-java DPKG is earlier than 6.0.24-2ubuntu1.7
  • OR tomcat6-docs DPKG is earlier than 6.0.24-2ubuntu1.7
  • OR libservlet2.5-java-doc DPKG is earlier than 6.0.24-2ubuntu1.7
  • OR tomcat6 DPKG is earlier than 6.0.24-2ubuntu1.7
  • OR tomcat6-admin DPKG is earlier than 6.0.24-2ubuntu1.7
  • OR tomcat6-common DPKG is earlier than 6.0.24-2ubuntu1.7
  • OR tomcat6-user DPKG is earlier than 6.0.24-2ubuntu1.7
  • OR tomcat6-examples DPKG is earlier than 6.0.24-2ubuntu1.7
  • BACK