Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian 7: DLA-1166-1 Critical: Tomcat7 Remote Code Execution

debian lts
Calendar Grey November 7, 2017
Dist Debian Esm H88
A critical security flaw allowing remote code execution in tomcat7 for Debian 7 has been detected and remedied in the new security patch.
A remote code execution vulnerability has been discovered in tomcat7

Summary

When HTTP PUT was enabled (e.g., via setting the readonly initialization
parameter of the Default servlet to false) it was possible to upload a JSP
file to the server via a specially crafted request. This JSP could then be
requested and any code it contained would be executed by the server.

For Debian 7 "Wheezy", these problems have been fixed in version
7.0.28-4+deb7u16.

We recommend that you upgrade your tomcat7 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: tomcat7
Version: 7.0.28-4+deb7u16
CVE ID: CVE-2017-12617

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here