USN-3519-1: Tomcat vulnerabilities
USN-3519-1: Tomcat vulnerabilities Ubuntu Security Notice USN-3519-1 8th January, 2018 tomcat7, tomcat8 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Tomcat. Software description tomcat7 – Servlet and JSP engine tomcat8 – Servlet and JSP engine Details It was discovered that Tomcat incorrectly handled certain pipelinedrequests when sendfile was used. A remote attacker could use this issue toobtain wrong responses possibly containing sensitive information.(CVE-2017-5647) It was discovered that Tomcat incorrectly used the appropriate facadeobject. A malicious application could possibly use this to bypass SecurityManager restrictions. (CVE-2017-5648) It was discovered that Tomcat incorrectly handled error pages. A remoteattacker could possibly use this issue to replace or remove the customerror page. (CVE-2017-5664) It was discovered that Tomcat incorrectly handled the CORS filter. A remoteattacker [ more… ]