Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE Linux 12-SP2: 2016:3081-1 Important Tomcat Remote Code Execution Fix

suse
Calendar Grey December 10, 2016
Dist Suse Esm H88
Essential SUSE patch for Apache addresses numerous vulnerabilities, improving Linux server reliability and performance.
An update that solves 7 vulnerabilities and has two fixes An update that solves 7 vulnerabilities and has two fixes An update that solves 7 vulnerabilities and has two fixes is now...

Summary

This update for tomcat fixes the following issues: Feature changes: The embedded Apache Commons DBCP component was updated to version 2.0. (bsc#1010893 fate#321029) Security fixes: - CVE-2016-0762: Realm Timing Attack (bsc#1007854) - CVE-2016-5018: Security Manager Bypass (bsc#1007855) - CVE-2016-6794: System Property Disclosure (bsc#1007857) - CVE-2016-6796: Security Manager Bypass (bsc#1007858) - CVE-2016-6797: Unrestricted Access to Global Resources (bsc#1007853) - CVE-2016-8735: Remote code execution vulnerability in JmxRemoteLifecycleListener (bsc#1011805) - CVE-2016-6816: HTTP Request smuggling vulnerability due to permitting invalid character in HTTP requests (bsc#1011812) Bug fixes: - Enabled optional setenv.sh script. See section '(3.4) Using the "setenv"

References

#1002639 #1007853 #1007854 #1007855 #1007857

#1007858 #1010893 #1011805 #1011812

Cross- CVE-2016-0762 CVE-2016-5018 CVE-2016-6794

CVE-2016-6796 CVE-2016-6797 CVE-2016-6816

CVE-2016-8735

Affected Products:

SUSE Linux Enterprise Server for Raspberry Pi 12-SP2

SUSE Linux Enterprise Server 12-SP2

https://www.suse.com/security/cve/CVE-2016-0762.html

https://www.suse.com/security/cve/CVE-2016-5018.html

https://www.suse.com/security/cve/CVE-2016-6794.html

https://www.suse.com/security/cve/CVE-2016-6796.html

https://www.suse.com/security/cve/CVE-2016-6797.html

https://www.suse.com/security/cve/CVE-2016-6816.html

https://www.suse.com/security/cve/CVE-2016-8735.html

https://bugzilla.suse.com/1002639

https://bugzilla.suse.com/1007853

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:3081-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here