Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 25 articles for you...
100

SUSE Linux Enterprise: 2021:14705-1 Important: Tomcat6 Security Fixes

An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for tomcat6 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:14705-1 Rating: important References: #1059554 #1180947 #1182909 Cross-References: CVE-2017-12617 CVE-2021-24122 CVE-2021-25329 CVSS scores: CVE-2017-12617 (NVD) : 8.1 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2017-12617 (SUSE): 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-24122 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2021-24122 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2021-25329 (NVD) : 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-25329 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for tomcat6 fixes the following issues: - CVE-2021-25329: Fixed completely CVE-2020-9484 (bsc#1182909). - CVE-2021-24122: Fixed an information disclosure (bsc#1180947). - CVE-2017-12617: Fixed a file inclusion vulnerability through a crafted request (bsc#1059554). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-tomcat6-14705=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-tomcat6-14705=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS(noarch): tomcat6-6.0.53-0.57.19.1 tomcat6-admin-webapps-6.0.53-0.57.19.1 tomcat6-docs-webapp-6.0.53-0.57.19.1 tomcat6-javadoc-6.0.53-0.57.19.1 tomcat6-jsp-2_1-api-6.0.53-0.57.19.1 tomcat6-lib-6.0.53-0.57.19.1 tomcat6-servlet-2_5-api-6.0.53-0.57.19.1 tomcat6-webapps-6.0.53-0.57.19.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (noarch): tomcat6-6.0.53-0.57.19.1 tomcat6-admin-webapps-6.0.53-0.57.19.1 tomcat6-docs-webapp-6.0.53-0.57.19.1 tomcat6-javadoc-6.0.53-0.57.19.1 tomcat6-jsp-2_1-api-6.0.53-0.57.19.1 tomcat6-lib-6.0.53-0.57.19.1 tomcat6-servlet-2_5-api-6.0.53-0.57.19.1 tomcat6-webapps-6.0.53-0.57.19.1 References: https://www.suse.com/security/cve/CVE-2017-12617.html https://www.suse.com/security/cve/CVE-2021-24122.html https://www.suse.com/security/cve/CVE-2021-25329.html https://bugzilla.suse.com/1059554 https://bugzilla.suse.com/1180947 https://bugzilla.suse.com/1182909 . SUSE Security Update 2022:19234-1: Critical update for nginx addressing various vulnerabilities to improve overall system integrity.. SUSE Linux Enterprise,TOMCAT6 Security Update,TOMCAT6 Vulnerability Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 21, 2021 Important SuSE
200

SciLinux: SLSA-2020:2529-1 Important: High RCE Risk for tomcat6

. Synopsis: Important: tomcat6 security update Advisory ID: SLSA-2020:2529-1 Issue Date: 2020-06-11 CVE Numbers: None -- * tomcat: deserialization flaw in session persistence storage leading to RCE (CVE-2020-9484) -- SL6 noarch tomcat6-6.0.24-115.el6_10.noarch.rpm tomcat6-admin-webapps-6.0.24-115.el6_10.noarch.rpm tomcat6-docs-webapp-6.0.24-115.el6_10.noarch.rpm tomcat6-el-2.1-api-6.0.24-115.el6_10.noarch.rpm tomcat6-javadoc-6.0.24-115.el6_10.noarch.rpm tomcat6-jsp-2.1-api-6.0.24-115.el6_10.noarch.rpm tomcat6-lib-6.0.24-115.el6_10.noarch.rpm tomcat6-servlet-2.5-api-6.0.24-115.el6_10.noarch.rpm tomcat6-webapps-6.0.24-115.el6_10.noarch.rpm - Scientific Linux Development Team . Important tomcat6 patch issued for a critical deserialization vulnerability that permits remote code execution. Immediate action is necessary.. Tomcat6 Update, SL6 Security, Remote Code Execution, Scientific Linux Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 12, 2020 Important Scientific Linux
100

SUSE: 2020:14375-1 Important: Tomcat6 Remote Code Execution Threat

An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for tomcat6 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:14375-1 Rating: important References: #1136085 #1159723 #1171928 Cross-References: CVE-2019-0221 CVE-2019-12418 CVE-2020-9484 Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for tomcat6 fixes the following issues: CVE-2020-9484 (bsc#1171928) Apache Tomcat Remote Code Execution via session persistence If an attacker was able to control the contents and name of a file on a server configured to use the PersistenceManager, then the attacker could have triggered a remote code execution via deserialization of the file under their control. CVE-2019-12418 (bsc#1159723) Local privilege escalation by manipulating the RMI registry and performing a man-in-the-middle attack When Tomcat is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files was able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker could then use these credentials to access the JMX interface and gain complete control over the Tomcat instance. CVE-2019-0221 (bsc#1136085) The SSI printenv command echoed user provided data without escaping, which made it vulnerable to XSS. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSELinux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-tomcat6-14375=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-tomcat6-14375=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (noarch): tomcat6-6.0.53-0.57.16.1 tomcat6-admin-webapps-6.0.53-0.57.16.1 tomcat6-docs-webapp-6.0.53-0.57.16.1 tomcat6-javadoc-6.0.53-0.57.16.1 tomcat6-jsp-2_1-api-6.0.53-0.57.16.1 tomcat6-lib-6.0.53-0.57.16.1 tomcat6-servlet-2_5-api-6.0.53-0.57.16.1 tomcat6-webapps-6.0.53-0.57.16.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (noarch): tomcat6-6.0.53-0.57.16.1 tomcat6-admin-webapps-6.0.53-0.57.16.1 tomcat6-docs-webapp-6.0.53-0.57.16.1 tomcat6-javadoc-6.0.53-0.57.16.1 tomcat6-jsp-2_1-api-6.0.53-0.57.16.1 tomcat6-lib-6.0.53-0.57.16.1 tomcat6-servlet-2_5-api-6.0.53-0.57.16.1 tomcat6-webapps-6.0.53-0.57.16.1 References: https://www.suse.com/security/cve/CVE-2019-0221.html https://www.suse.com/security/cve/CVE-2019-12418.html https://www.suse.com/security/cve/CVE-2020-9484.html https://bugzilla.suse.com/1136085 https://bugzilla.suse.com/1159723 https://bugzilla.suse.com/1171928 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE has issued a security patch for tomcat6 addressing critical weaknesses, thereby improving system safety.. SUSE Linux, tomcat6 updates, security fixes, remote code execution, local privilege escalation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 22, 2020 Important SuSE
100

SUSE: 2020:14334-1 Important: Tomcat6 File Disclosure Fix

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for tomcat6 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:14334-1 Rating: important References: #1164692 Cross-References: CVE-2020-1938 Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for tomcat6 fixes the following issues: - CVE-2020-1938: Fixed a file contents disclosure vulnerability (bsc#1164692). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-tomcat6-14334=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-tomcat6-14334=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (noarch): tomcat6-6.0.53-0.57.13.1 tomcat6-admin-webapps-6.0.53-0.57.13.1 tomcat6-docs-webapp-6.0.53-0.57.13.1 tomcat6-javadoc-6.0.53-0.57.13.1 tomcat6-jsp-2_1-api-6.0.53-0.57.13.1 tomcat6-lib-6.0.53-0.57.13.1 tomcat6-servlet-2_5-api-6.0.53-0.57.13.1 tomcat6-webapps-6.0.53-0.57.13.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (noarch): tomcat6-6.0.53-0.57.13.1 tomcat6-admin-webapps-6.0.53-0.57.13.1 tomcat6-docs-webapp-6.0.53-0.57.13.1 tomcat6-javadoc-6.0.53-0.57.13.1 tomcat6-jsp-2_1-api-6.0.53-0.57.13.1 tomcat6-lib-6.0.53-0.57.13.1 tomcat6-servlet-2_5-api-6.0.53-0.57.13.1 tomcat6-webapps-6.0.53-0.57.13.1 References: https://www.suse.com/security/cve/CVE-2020-1938.html https://bugzilla.suse.com/1164692 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Update for tomcat7 tackles a significant vulnerability related to information exposure, with detailed remediation steps available.. SUSE Updates, Tomcat6 Fixes, Linux Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 27, 2020 Important SuSE
199

CentOS: CESA-2020-0912 Important: Tomcat6 High Severity Issue

Upstream details at : https://access.redhat.com/errata/RHSA-2020:0912. CentOS Errata and Security Advisory 2020:0912 Important Upstream details at : https://access.redhat.com/errata/RHSA-2020:0912 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) i386: 1f31df5053d2c93b8844fc06705226e08f8b4ffda26b741ee3394ac033621b5e tomcat6-6.0.24-114.el6_10.noarch.rpm e3087f026652ae767095701fd7e6b0314ad6e40574711edcaabaa37a12a28c82 tomcat6-admin-webapps-6.0.24-114.el6_10.noarch.rpm d2e3fb2a4042fbaac5ad2985581a0ce64479a18b9a5e21f53c0fe3aa99ec238d tomcat6-docs-webapp-6.0.24-114.el6_10.noarch.rpm 802628047af1ce14071227187c775a74aea464bae3bcafdf82eebe56b3972ad9 tomcat6-el-2.1-api-6.0.24-114.el6_10.noarch.rpm 5b9500612c9ac7ee533525a89bde239c95ed906d9b7500443e4a05f33ffd052f tomcat6-javadoc-6.0.24-114.el6_10.noarch.rpm 00a5f3c5c26b67c96a6708f0e77ee8db4db7ba4eff45afed075fd131243597d4 tomcat6-jsp-2.1-api-6.0.24-114.el6_10.noarch.rpm 049e09d3b6d20dfd3f9dc8bb9e0b4e990d7f18a8b65eb6a99b6e4a5bb6ab2f68 tomcat6-lib-6.0.24-114.el6_10.noarch.rpm ef82651f7d5f1003f2a27db152bc3b60d118f0f444ac14c42edef641fa825f5c tomcat6-servlet-2.5-api-6.0.24-114.el6_10.noarch.rpm 0134d6af3f09ea958aee1e4a860ed3a5bfbc9ffbb8800f15f88fc6461f1c2773 tomcat6-webapps-6.0.24-114.el6_10.noarch.rpm x86_64: 1f31df5053d2c93b8844fc06705226e08f8b4ffda26b741ee3394ac033621b5e tomcat6-6.0.24-114.el6_10.noarch.rpm e3087f026652ae767095701fd7e6b0314ad6e40574711edcaabaa37a12a28c82 tomcat6-admin-webapps-6.0.24-114.el6_10.noarch.rpm d2e3fb2a4042fbaac5ad2985581a0ce64479a18b9a5e21f53c0fe3aa99ec238d tomcat6-docs-webapp-6.0.24-114.el6_10.noarch.rpm 802628047af1ce14071227187c775a74aea464bae3bcafdf82eebe56b3972ad9 tomcat6-el-2.1-api-6.0.24-114.el6_10.noarch.rpm 5b9500612c9ac7ee533525a89bde239c95ed906d9b7500443e4a05f33ffd052f tomcat6-javadoc-6.0.24-114.el6_10.noarch.rpm 00a5f3c5c26b67c96a6708f0e77ee8db4db7ba4eff45afed075fd131243597d4 tomcat6-jsp-2.1-api-6.0.24-114.el6_10.noarch.rpm 049e09d3b6d20dfd3f9dc8bb9e0b4e990d7f18a8b65eb6a99b6e4a5bb6ab2f68 tomcat6-lib-6.0.24-114.el6_10.noarch.rpm ef82651f7d5f1003f2a27db152bc3b60d118f0f444ac14c42edef641fa825f5c tomcat6-servlet-2.5-api-6.0.24-114.el6_10.noarch.rpm 0134d6af3f09ea958aee1e4a860ed3a5bfbc9ffbb8800f15f88fc6461f1c2773 tomcat6-webapps-6.0.24-114.el6_10.noarch.rpm Source: 18ecd659c0eac0e737adbba7ca1cf2cbdd4d86504a6cbe7877e3ea9f2c5185b5 tomcat6-6.0.24-114.el6_10.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #This email address is being protected from spambots. You need JavaScript enabled to view it. Twitter: @JohnnyCentOS _______________________________________________ CentOS-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Review the significant CentOS Errata and Security Advisory 2020:0912 for crucial information on vulnerabilities associated with tomcat6.. CentOS Errata, tomcat6 update, security advisory, CentOS security, important updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 25, 2020 Important CentOS
100

SUSE: 2019:4510-1 Moderate: Tomcat7 Vulnerability Patch

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for tomcat6 ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:3935-1 Rating: moderate References: #1110850 Cross-References: CVE-2018-11784 Affected Products: SUSE Linux Enterprise Server 11-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for tomcat6 fixes the following issue: Security issue fixed: - CVE-2018-11784: Fixed problem with specially crafted URLs that could be used to cause a redirect to any URI of an attackers choise (bsc#1110850). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-tomcat6-13884=1 Package List: - SUSE Linux Enterprise Server 11-SP4 (noarch): tomcat6-6.0.53-0.57.10.1 tomcat6-admin-webapps-6.0.53-0.57.10.1 tomcat6-docs-webapp-6.0.53-0.57.10.1 tomcat6-javadoc-6.0.53-0.57.10.1 tomcat6-jsp-2_1-api-6.0.53-0.57.10.1 tomcat6-lib-6.0.53-0.57.10.1 tomcat6-servlet-2_5-api-6.0.53-0.57.10.1 tomcat6-webapps-6.0.53-0.57.10.1 References: https://www.suse.com/security/cve/CVE-2018-11784.html https://bugzilla.suse.com/1110850 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Notice resolves an issue in tomcat7 and includes guidelines for users to apply the patch.. SUSE Updates,TOMCAT6 Patches,SUSE Security Advisory. . LinuxSecurity.com Team

Calendar%202 Nov 28, 2018 SuSE
100

SUSE Linux 11-SP4: Advisory ID 2017:1632-1 Critical Tomcat6 Remote Exec

An update that solves 10 vulnerabilities and has one errata An update that solves 10 vulnerabilities and has one errata An update that solves 10 vulnerabilities and has one errata is now available. is now available.. SUSE Security Update: Security update for tomcat6 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1632-1 Rating: important References: #1007853 #1007854 #1007855 #1007857 #1007858 #1011805 #1011812 #1015119 #1033448 #1036642 #988489 Cross-References: CVE-2016-0762 CVE-2016-5018 CVE-2016-5388 CVE-2016-6794 CVE-2016-6796 CVE-2016-6797 CVE-2016-6816 CVE-2016-8735 CVE-2016-8745 CVE-2017-5647 Affected Products: SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Server 11-SP3-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 ______________________________________________________________________________ An update that solves 10 vulnerabilities and has one errata is now available. Description: This update for tomcat6 fixes the following issues: Tomcat was updated to version 6.0.53: The full changelog is: http://tomcat.apache.org/tomcat-6.0-doc/changelog.html Security issues fixed: - CVE-2017-5647: A bug in the handling of pipelined requests could lead to information disclosure (bsc#1036642) - CVE-2016-8745: Regression in the error handling methods could lead to information disclosure (bsc#1015119) - CVE-2016-8735: Remote code execution vulnerability in JmxRemoteLifecycleListener (bsc#1011805) - CVE-2016-6816: HTTP Request smuggling vulnerability due to permitting invalid character in HTTP requests (bsc#1011812) - CVE-2016-6797: Unrestricted Access to Global Resources (bsc#1007853) - CVE-2016-6796: Manager Bypass (bsc#1007858) - CVE-2016-6794: System Property Disclosure (bsc#1007857) - CVE-2016-5018: Security Manager Bypass (bsc#1007855) - CVE-2016-0762: Realm Timing Attack (bsc#1007854) - CVE-2016-5388: an arbitrary HTTP_PROXY environment variable might allow remote attackers to redirect outbound HTTP traffic (bsc#988489) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-tomcat6-13162=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-tomcat6-13162=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-tomcat6-13162=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11-SP4 (noarch): tomcat6-6.0.53-0.56.1 tomcat6-admin-webapps-6.0.53-0.56.1 tomcat6-docs-webapp-6.0.53-0.56.1 tomcat6-javadoc-6.0.53-0.56.1 tomcat6-jsp-2_1-api-6.0.53-0.56.1 tomcat6-lib-6.0.53-0.56.1 tomcat6-servlet-2_5-api-6.0.53-0.56.1 tomcat6-webapps-6.0.53-0.56.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (noarch): tomcat6-6.0.53-0.56.1 tomcat6-admin-webapps-6.0.53-0.56.1 tomcat6-docs-webapp-6.0.53-0.56.1 tomcat6-javadoc-6.0.53-0.56.1 tomcat6-jsp-2_1-api-6.0.53-0.56.1 tomcat6-lib-6.0.53-0.56.1 tomcat6-servlet-2_5-api-6.0.53-0.56.1 tomcat6-webapps-6.0.53-0.56.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (noarch): tomcat6-6.0.53-0.56.1 tomcat6-admin-webapps-6.0.53-0.56.1 tomcat6-docs-webapp-6.0.53-0.56.1 tomcat6-javadoc-6.0.53-0.56.1 tomcat6-jsp-2_1-api-6.0.53-0.56.1 tomcat6-lib-6.0.53-0.56.1 tomcat6-servlet-2_5-api-6.0.53-0.56.1 tomcat6-webapps-6.0.53-0.56.1 References: https://www.suse.com/security/cve/CVE-2016-0762.html https://www.suse.com/security/cve/CVE-2016-5018.html https://www.suse.com/security/cve/CVE-2016-5388.html https://www.suse.com/security/cve/CVE-2016-6794.html https://www.suse.com/security/cve/CVE-2016-6796.html https://www.suse.com/security/cve/CVE-2016-6797.html https://www.suse.com/security/cve/CVE-2016-6816.html https://www.suse.com/security/cve/CVE-2016-8735.html https://www.suse.com/security/cve/CVE-2016-8745.html https://www.suse.com/security/cve/CVE-2017-5647.html https://bugzilla.suse.com/1007853 https://bugzilla.suse.com/1007854 https://bugzilla.suse.com/1007855 https://bugzilla.suse.com/1007857 https://bugzilla.suse.com/1007858 https://bugzilla.suse.com/1011805 https://bugzilla.suse.com/1011812 https://bugzilla.suse.com/1015119 https://bugzilla.suse.com/1033448 https://bugzilla.suse.com/1036642 https://bugzilla.suse.com/988489 . A new patch for tomcat6 has been released addressing 10 significant vulnerabilities that include information exposure and potential remote code execution risks.. SUSE Linux, Tomcat Security, Remote Execution, Threat Mitigation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 21, 2017 Important SuSE
98

Red Hat Enterprise Linux 6: Security Update for Tomcat6 RHSA-2017-0527-01

An update for tomcat6 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: tomcat6 security update Advisory ID: RHSA-2017:0527-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2017:0527.html Issue date: 2017-03-15 CVE Names: CVE-2016-6816 CVE-2016-8745 ==================================================================== 1. Summary: An update for tomcat6 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Optional (v. 6) - noarch Red Hat Enterprise Linux HPC Node Optional (v. 6) - noarch Red Hat Enterprise Linux Server (v. 6) - noarch Red Hat Enterprise Linux Server Optional (v. 6) - noarch Red Hat Enterprise Linux Workstation (v. 6) - noarch Red Hat Enterprise Linux Workstation Optional (v. 6) - noarch 3. Description: Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * It was discovered that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSSattack, or obtain sensitive information from requests other then their own. (CVE-2016-6816) Note: This fix causes Tomcat to respond with an HTTP 400 Bad Request error when request contains characters that are not permitted by the HTTP specification to appear not encoded, even though they were previously accepted. The newly introduced system property tomcat.util.http.parser.HttpParser.requestTargetAllow can be used to configure Tomcat to accept curly braces ({ and }) and the pipe symbol (|) in not encoded form, as these are often used in URLs without being properly encoded. * A bug was discovered in the error handling of the send file code for the NIO HTTP connector. This led to the current Processor object being added to the Processor cache multiple times allowing information leakage between requests including, and not limited to, session ID and the response body. (CVE-2016-8745) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1397484 - CVE-2016-6816 tomcat: HTTP Request smuggling vulnerability due to permitting invalid character in HTTP requests 1403824 - CVE-2016-8745 tomcat: information disclosure due to incorrect Processor sharing 6. Package List: Red Hat Enterprise Linux Desktop Optional (v. 6): Source: tomcat6-6.0.24-105.el6_8.src.rpm noarch: tomcat6-6.0.24-105.el6_8.noarch.rpm tomcat6-admin-webapps-6.0.24-105.el6_8.noarch.rpm tomcat6-docs-webapp-6.0.24-105.el6_8.noarch.rpm tomcat6-el-2.1-api-6.0.24-105.el6_8.noarch.rpm tomcat6-javadoc-6.0.24-105.el6_8.noarch.rpm tomcat6-jsp-2.1-api-6.0.24-105.el6_8.noarch.rpm tomcat6-lib-6.0.24-105.el6_8.noarch.rpm tomcat6-servlet-2.5-api-6.0.24-105.el6_8.noarch.rpm tomcat6-webapps-6.0.24-105.el6_8.noarch.rpm Red Hat Enterprise Linux HPC Node Optional (v.6): Source: tomcat6-6.0.24-105.el6_8.src.rpm noarch: tomcat6-6.0.24-105.el6_8.noarch.rpm tomcat6-admin-webapps-6.0.24-105.el6_8.noarch.rpm tomcat6-docs-webapp-6.0.24-105.el6_8.noarch.rpm tomcat6-el-2.1-api-6.0.24-105.el6_8.noarch.rpm tomcat6-javadoc-6.0.24-105.el6_8.noarch.rpm tomcat6-jsp-2.1-api-6.0.24-105.el6_8.noarch.rpm tomcat6-lib-6.0.24-105.el6_8.noarch.rpm tomcat6-servlet-2.5-api-6.0.24-105.el6_8.noarch.rpm tomcat6-webapps-6.0.24-105.el6_8.noarch.rpm Red Hat Enterprise Linux Server (v. 6): Source: tomcat6-6.0.24-105.el6_8.src.rpm noarch: tomcat6-6.0.24-105.el6_8.noarch.rpm tomcat6-el-2.1-api-6.0.24-105.el6_8.noarch.rpm tomcat6-jsp-2.1-api-6.0.24-105.el6_8.noarch.rpm tomcat6-lib-6.0.24-105.el6_8.noarch.rpm tomcat6-servlet-2.5-api-6.0.24-105.el6_8.noarch.rpm Red Hat Enterprise Linux Server Optional (v. 6): Source: tomcat6-6.0.24-105.el6_8.src.rpm noarch: tomcat6-admin-webapps-6.0.24-105.el6_8.noarch.rpm tomcat6-docs-webapp-6.0.24-105.el6_8.noarch.rpm tomcat6-javadoc-6.0.24-105.el6_8.noarch.rpm tomcat6-webapps-6.0.24-105.el6_8.noarch.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: tomcat6-6.0.24-105.el6_8.src.rpm noarch: tomcat6-6.0.24-105.el6_8.noarch.rpm tomcat6-el-2.1-api-6.0.24-105.el6_8.noarch.rpm tomcat6-jsp-2.1-api-6.0.24-105.el6_8.noarch.rpm tomcat6-lib-6.0.24-105.el6_8.noarch.rpm tomcat6-servlet-2.5-api-6.0.24-105.el6_8.noarch.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: tomcat6-6.0.24-105.el6_8.src.rpm noarch: tomcat6-admin-webapps-6.0.24-105.el6_8.noarch.rpm tomcat6-docs-webapp-6.0.24-105.el6_8.noarch.rpm tomcat6-javadoc-6.0.24-105.el6_8.noarch.rpm tomcat6-webapps-6.0.24-105.el6_8.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2016-6816 https://access.redhat.com/security/cve/CVE-2016-8745 https://access.redhat.com/security/updates/classification/#moderate 8.Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFYyUfJXlSAg2UNWIIRAkTcAKCDm0ks64tetMz1A5Ui5bTODMeXCQCgreFB 8LuRSPjXmcOCIpY9D4+w5R0=OgIl -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical security patch released for apache-tomcat in RHEL 7 tackles significant vulnerabilities. Ensure your systems are secure!. Red Hat Enterprise Linux,tomcat6 security update,moderate advisory,CVE-2016-6816,CVE-2016-8745. . LinuxSecurity.com Team

Calendar%202 Mar 15, 2017 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200