Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Fedora 25: 2017-376ae2b92c Critical: Tomcat Information Disclosure

fedora
Calendar Grey February 22, 2017
Scroller Fedora
The recent Fedora update for Tomcat tackles CVE-2016-8745, enhancing safeguards against potential information leaks.
Security fix for CVE-2016-8745

Summary

Tomcat is the servlet container that is used in the official Reference

Implementation for the Java Servlet and JavaServer Pages technologies.

The Java Servlet and JavaServer Pages specifications are developed by

Sun under the Java Community Process.

Tomcat is developed in an open and participatory environment and

released under the Apache Software License version 2.0. Tomcat is intended

to be a collaboration of the best-of-breed developers from around the world.

Update Information:

Security fix for CVE-2016-8745

Change Log

References


[ 1 ] Bug #1403824 - CVE-2016-8745 tomcat: information disclosure due to incorrect Processor sharing https://bugzilla.redhat.com/show_bug.cgi?id=1403824

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade tomcat' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: tomcat
Product: Fedora 25
Version: 8.0.41
Release: 1.fc25
Summary: Apache Servlet/JSP Engine, RI for Servlet 3.1/JSP 2.3 API

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.