Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Ubuntu 13.10 USN-2130-1 Critical: Tomcat Request Smuggling Threat

ubuntu
Calendar Grey March 6, 2014
Scroller Ubuntu
Alert Update USN-2130-1 addresses vital security patches for Tomcat in Ubuntu distributions. Ensure your machines are updated to safeguard against potential threats.
Several security issues were fixed in Tomcat.

Summary

Several security issues were fixed in Tomcat.

Software Description:

- tomcat7: Servlet and JSP engine

- tomcat6: Servlet and JSP engine

Details:

It was discovered that Tomcat incorrectly handled certain inconsistent

HTTP headers. A remote attacker could possibly use this flaw to conduct

request smuggling attacks. (CVE-2013-4286)

It was discovered that Tomcat incorrectly handled certain requests

submitted using chunked transfer encoding. A remote attacker could use this

flaw to cause the Tomcat server to stop responding, resulting in a denial

of service. (CVE-2013-4322)

It was discovered that Tomcat incorrectly applied the disableURLRewriting

setting when handling a session id in a URL. A remote attacker could

possibly use this flaw to conduct session fixation attacks. This issue

only applied to Ubuntu 12.04 LTS. (CVE-2014-0033)

It was discovered that Tomcat incorrectly handled malformed Content-Type

headers and multipart requests. A remote attacker cou...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  libtomcat7-java                 7.0.42-1ubuntu0.1

Ubuntu 12.10:
  libtomcat7-java                 7.0.30-0ubuntu1.3

Ubuntu 12.04 LTS:
  libtomcat6-java                 6.0.35-1ubuntu3.4

Ubuntu 10.04 LTS:
  libtomcat6-java                 6.0.24-2ubuntu1.15

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2130-1

CVE-2013-4286, CVE-2013-4322, CVE-2014-0033, CVE-2014-0050

Severity
critical
Lowest
Low
Medium
High
Critical

March 06, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.