Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2007-0569

Опубликовано: 17 июл. 2007
Источник: oracle-oval
Платформа: Oracle Linux 5

Описание

ELSA-2007-0569: Moderate: tomcat security update (MODERATE)

[5.5.23-0jpp.1.0.4.el5]

  • Remove erroneous rebuild-gcj-db for javadoc subpackage
  • Add fixes for CVE-2007-2449 and CVE-2007-2450
  • resolves: bug 244846, bug 244816

Обновленные пакеты

Oracle Linux 5

Oracle Linux x86_64

tomcat5

5.5.23-0jpp.1.0.4.el5

tomcat5-admin-webapps

5.5.23-0jpp.1.0.4.el5

tomcat5-common-lib

5.5.23-0jpp.1.0.4.el5

tomcat5-jasper

5.5.23-0jpp.1.0.4.el5

tomcat5-jasper-javadoc

5.5.23-0jpp.1.0.4.el5

tomcat5-jsp-2.0-api

5.5.23-0jpp.1.0.4.el5

tomcat5-jsp-2.0-api-javadoc

5.5.23-0jpp.1.0.4.el5

tomcat5-server-lib

5.5.23-0jpp.1.0.4.el5

tomcat5-servlet-2.4-api

5.5.23-0jpp.1.0.4.el5

tomcat5-servlet-2.4-api-javadoc

5.5.23-0jpp.1.0.4.el5

tomcat5-webapps

5.5.23-0jpp.1.0.4.el5

Oracle Linux i386

tomcat5

5.5.23-0jpp.1.0.4.el5

tomcat5-admin-webapps

5.5.23-0jpp.1.0.4.el5

tomcat5-common-lib

5.5.23-0jpp.1.0.4.el5

tomcat5-jasper

5.5.23-0jpp.1.0.4.el5

tomcat5-jasper-javadoc

5.5.23-0jpp.1.0.4.el5

tomcat5-jsp-2.0-api

5.5.23-0jpp.1.0.4.el5

tomcat5-jsp-2.0-api-javadoc

5.5.23-0jpp.1.0.4.el5

tomcat5-server-lib

5.5.23-0jpp.1.0.4.el5

tomcat5-servlet-2.4-api

5.5.23-0jpp.1.0.4.el5

tomcat5-servlet-2.4-api-javadoc

5.5.23-0jpp.1.0.4.el5

tomcat5-webapps

5.5.23-0jpp.1.0.4.el5

Связанные CVE

Связанные уязвимости

ubuntu
около 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.

redhat
около 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.

nvd
около 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.

debian
около 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager ...

ubuntu
около 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ';' character, as demonstrated by a URI containing a "snp/snoop.jsp;" sequence.