Описание
ELSA-2008-0648: tomcat security update (IMPORTANT)
[5.5.23-0jpp.7.el5_2.1]
- add patch for CVE-2008-1232 Resolves: rhbz#457727
- add patch for CVE-2008-1947 Resolves: rhbz#449916
- add patch for CVE-2008-2370 Resolves: rhbz#458634
- add patch for CVE-2008-2938 Resolves: rhbz#456214
Обновленные пакеты
Oracle Linux 5
Oracle Linux x86_64
tomcat5
5.5.23-0jpp.7.el5_2.1
tomcat5-admin-webapps
5.5.23-0jpp.7.el5_2.1
tomcat5-common-lib
5.5.23-0jpp.7.el5_2.1
tomcat5-jasper
5.5.23-0jpp.7.el5_2.1
tomcat5-jasper-javadoc
5.5.23-0jpp.7.el5_2.1
tomcat5-jsp-2.0-api
5.5.23-0jpp.7.el5_2.1
tomcat5-jsp-2.0-api-javadoc
5.5.23-0jpp.7.el5_2.1
tomcat5-server-lib
5.5.23-0jpp.7.el5_2.1
tomcat5-servlet-2.4-api
5.5.23-0jpp.7.el5_2.1
tomcat5-servlet-2.4-api-javadoc
5.5.23-0jpp.7.el5_2.1
tomcat5-webapps
5.5.23-0jpp.7.el5_2.1
Oracle Linux i386
tomcat5
5.5.23-0jpp.7.el5_2.1
tomcat5-admin-webapps
5.5.23-0jpp.7.el5_2.1
tomcat5-common-lib
5.5.23-0jpp.7.el5_2.1
tomcat5-jasper
5.5.23-0jpp.7.el5_2.1
tomcat5-jasper-javadoc
5.5.23-0jpp.7.el5_2.1
tomcat5-jsp-2.0-api
5.5.23-0jpp.7.el5_2.1
tomcat5-jsp-2.0-api-javadoc
5.5.23-0jpp.7.el5_2.1
tomcat5-server-lib
5.5.23-0jpp.7.el5_2.1
tomcat5-servlet-2.4-api
5.5.23-0jpp.7.el5_2.1
tomcat5-servlet-2.4-api-javadoc
5.5.23-0jpp.7.el5_2.1
tomcat5-webapps
5.5.23-0jpp.7.el5_2.1
Связанные CVE
Связанные уязвимости
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.3 ...