Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Ubuntu 16.04 LTS USN-3081-1 Moderate: Tomcat Remote Access Risk

ubuntu
Calendar Grey September 19, 2016
Scroller Ubuntu
A critical Tomcat security vulnerability in Ubuntu versions has prompted an urgent update to prevent unauthorized remote access by administrators, enhancing system safety
The system could be made to run programs as an administrator.

Summary

The system could be made to run programs as an administrator.

Software Description:

- tomcat8: Servlet and JSP engine

- tomcat7: Servlet and JSP engine

- tomcat6: Servlet and JSP engine

Details:

Dawid Golunski discovered that the Tomcat init script incorrectly handled

creating log files. A remote attacker could possibly use this issue to obtain

root privileges. (CVE-2016-1240)

This update also reverts a change in behaviour introduced in USN-3024-1 by

setting mapperContextRootRedirectEnabled to True by default.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  libtomcat8-java                 8.0.32-1ubuntu1.2
  tomcat8                         8.0.32-1ubuntu1.2

Ubuntu 14.04 LTS:
  libtomcat7-java                 7.0.52-1ubuntu0.7
  tomcat7                         7.0.52-1ubuntu0.7

Ubuntu 12.04 LTS:
  libtomcat6-java                 6.0.35-1ubuntu3.8
  tomcat6                         6.0.35-1ubuntu3.8

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3081-1

CVE-2016-1240, https://bugs.launchpad.net/ubuntu/+source/tomcat7/+bug/1609819

Severity
important
Lowest
Low
Medium
High
Critical

September 19, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.