USN-3177-1: Tomcat vulnerabilities Ubuntu Security Notice USN-3177-1 23rd January, 2017 tomcat6, tomcat7, tomcat8 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in Tomcat. Software description tomcat6 – Servlet and JSP engine tomcat7 – Servlet and JSP engine tomcat8 – Servlet and JSP engine Details It was discovered that the Tomcat realm implementations incorrectly handledpasswords when a username didn't exist. A remote attacker could possiblyuse this issue to enumerate usernames. This issue only applied to Ubuntu12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-0762) Alvaro Munoz and Alexander Mirosh discovered that Tomcat incorrectlylimited use of a certain utility method. A malicious application couldpossibly use this to bypass Security Manager restrictions. This issue onlyapplied to Ubuntu 12.04 LTS, Ubuntu 14.04 [ more… ]