[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2401-1 tomcat6 -- several

ID: oval:org.secpod.oval:def:600727Date: (C)2012-02-13   (M)2023-11-09
Class: PATCHFamily: unix




Several vulnerabilities have been found in Tomcat, a servlet and JSP engine: CVE-2011-1184 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 The HTTP Digest Access Authentication implementation performed insufficient countermeasures against replay attacks. CVE-2011-2204 In rare setups passwords were written into a logfile. CVE-2011-2526 Missing input sanisiting in the HTTP APR or HTTP NIO connectors could lead to denial of service. CVE-2011-3190 AJP requests could be spoofed in some setups. CVE-2011-3375 Incorrect request caching could lead to information disclosure. CVE-2011-4858 CVE-2012-0022 This update adds countermeasures against a collision denial of service vulnerability in the Java hashtable implementation and addresses denial of service potentials when processing large amounts of requests

Platform:
Debian 6.0
Product:
tomcat6
Reference:
DSA-2401-1
CVE-2011-1184
CVE-2011-2204
CVE-2011-2526
CVE-2011-3190
CVE-2011-3375
CVE-2011-4858
CVE-2011-5062
CVE-2011-5063
CVE-2011-5064
CVE-2012-0022
CVE    10
CVE-2011-1184
CVE-2011-2526
CVE-2011-3375
CVE-2011-3190
...
CPE    98
cpe:/a:apache:tomcat:6.0
cpe:/a:apache:tomcat:6
cpe:/a:apache:tomcat:6.0.9
cpe:/a:apache:tomcat:6.0.8
...

© SecPod Technologies