Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
USN-8369-1 introduced a regression in mod_jk
Software Description:
- libapache-mod-jk: Apache 2 connector for the Tomcat Java servlet engine
Details:
USN-8369-1 fixed a vulnerability in mod_jk. It was discovered that for
Ubuntu 18.04 LTS, during the update preparation phase, a previous fix for
CVE-2023-41081 was incorrectly dropped. This update reintroduces the fix
for CVE-2023-41081.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Apache Tomcat Connectors used incorrect default
permissions for shared memory on Unix-like systems. A local attacker could
possibly use this issue to view or modify mod_jk configuration data in
shared memory, resulting in sensitive information exposure or a denial of
service.
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS
libapache2-mod-jk 1:1.2.41-1ubuntu0.1~esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.https://ubuntu.com/security/notices/USN-8369-2
https://ubuntu.com/security/notices/USN-8369-1
CVE-2023-41081, https://launchpad.net/bugs/2161580
Get the latest Linux and open source security news straight to your inbox.