Ubuntu security notices
USN-3081-1: Tomcat vulnerability
USN-3081-1: Tomcat vulnerability Ubuntu Security Notice USN-3081-1 19th September, 2016 tomcat6, tomcat7, tomcat8 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary The system could be made to run programs as an administrator. Software description tomcat6 – Servlet and JSP engine tomcat7 – Servlet and JSP engine tomcat8 – Servlet and JSP engine Details Dawid Golunski discovered that the Tomcat init script incorrectly handledcreating log files. A remote attacker could possibly use this issue to obtain root privileges. (CVE-2016-1240) This update also reverts a change in behaviour introduced in USN-3024-1 bysetting mapperContextRootRedirectEnabled to True by default. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: libtomcat8-java 8.0.32-1ubuntu1.2 tomcat8 8.0.32-1ubuntu1.2 Ubuntu 14.04 LTS: tomcat7 7.0.52-1ubuntu0.7 libtomcat7-java 7.0.52-1ubuntu0.7 Ubuntu [ more… ]