Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2017:3059-1 Important: Tomcat Remote Code Execution Risk

suse
Calendar Grey November 23, 2017
Dist Suse Esm H88
SUSE unveils security patch for Tomcat which tackles severe vulnerabilities. Safeguard your infrastructure by applying updates promptly.
An update that fixes 5 vulnerabilities is now available

Summary

Apache Tomcat was updated to 7.0.82 adding features, fixing bugs and security issues. This is another bugfix release, for full details see: https://tomcat.apache.org/tomcat-7.0-doc/changelog.html Fixed security issues: - CVE-2017-5664: A problem in handling error pages was fixed, to avoid potential file overwrites during error page handling. (bsc#1042910). - CVE-2017-7674: A CORS Filter issue could lead to client and server side cache poisoning (bsc#1053352) - CVE-2017-12617: A remote code execution possibility via JSP Upload was fixed (bsc#1059554) - CVE-2017-12616: An information disclosure when using VirtualDirContext was fixed (bsc#1059551) - CVE-2017-12615: A Remote Code Execution via JSP Upload was fixed (bsc#1059554) Non-security issues fixed:

References

#1042910 #1053352 #1059551 #1059554 #977410

Cross- CVE-2017-12615 CVE-2017-12616 CVE-2017-12617

CVE-2017-5664 CVE-2017-7674

Affected Products:

SUSE Linux Enterprise Server 12-LTSS

https://www.suse.com/security/cve/CVE-2017-12615.html

https://www.suse.com/security/cve/CVE-2017-12616.html

https://www.suse.com/security/cve/CVE-2017-12617.html

https://www.suse.com/security/cve/CVE-2017-5664.html

https://www.suse.com/security/cve/CVE-2017-7674.html

https://bugzilla.suse.com/1042910

https://bugzilla.suse.com/1053352

https://bugzilla.suse.com/1059551

https://bugzilla.suse.com/1059554

https://bugzilla.suse.com/977410

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:3059-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here