Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Debian: DSA-2897-1 Critical: Tomcat7 Remote Exploits Detected

debian
Calendar Grey April 8, 2014
Scroller Debian
Various vulnerabilities addressed in tomcat7 impacting Debian environments. Make sure to refresh your packages to reduce exposure.
Multiple security issues were found in the Tomcat servlet and JSP engine: CVE-2013-2067

Summary

Multiple security issues were found in the Tomcat servlet and JSP engine:

CVE-2013-2067

FORM authentication associates the most recent request requiring
authentication with the current session. By repeatedly sending a request
for an authenticated resource while the victim is completing the login
form, an attacker could inject a request that would be executed using the
victim's credentials.

CVE-2013-2071

A runtime exception in AsyncListener.onComplete() prevents the request from
being recycled. This may expose elements of a previous request to a current
request.

CVE-2013-4286

Reject requests with multiple content-length headers or with a content-length
header when chunked encoding is being used.

CVE-2013-4322

When processing a request submitted using the chunked transfer encoding,
Tomcat ignored but did not limit any extensions that were included. This allows
a client to perform a limited denial of service. by streaming an unlimited amount
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: tomcat7
CVE ID: CVE-2013-2067 CVE-2013-2071 CVE-2013-4286 CVE-2013-4322

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.