Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Ubuntu 11.10 USN-1359-1 Critical: Tomcat Denial Of Service

ubuntu
Calendar Grey February 13, 2012
Scroller Ubuntu
Apache Tomcat weaknesses in Ubuntu may result in system failures or reveal confidential data via specially forged network packets.
Tomcat could be made to crash or expose sensitive information if it received specially crafted network traffic.

Summary

Tomcat could be made to crash or expose sensitive information if it

received specially crafted network traffic.

Software Description:

- tomcat6: Servlet and JSP engine

Details:

It was discovered that Tomcat incorrectly performed certain caching and

recycling operations. A remote attacker could use this flaw to obtain read

access to IP address and HTTP header information in certain cases. This

issue only applied to Ubuntu 11.10. (CVE-2011-3375)

It was discovered that Tomcat computed hash values for form parameters

without restricting the ability to trigger hash collisions predictably.

A remote attacker could cause a denial of service by sending many crafted

parameters. (CVE-2011-4858)

It was discovered that Tomcat incorrectly handled parameters. A remote

attacker could cause a denial of service by sending requests with a large

number of parameters and values. (CVE-2012-0022)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  libtomcat6-java                 6.0.32-5ubuntu1.2

Ubuntu 11.04:
  libtomcat6-java                 6.0.28-10ubuntu2.3

Ubuntu 10.10:
  libtomcat6-java                 6.0.28-2ubuntu1.6

Ubuntu 10.04 LTS:
  libtomcat6-java                 6.0.24-2ubuntu1.10

In general, a standard system update will make all the necessary changes.

References

CVE-2011-3375, CVE-2011-4858, CVE-2012-0022

Severity
critical
Lowest
Low
Medium
High
Critical

February 13, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.