Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:3453-1

Опубликовано: 25 окт. 2018
Источник: suse-cvrf

Описание

Security update for tomcat

This update for tomcat fixes the following issues:

  • CVE-2018-11784: When the default servlet in Apache Tomcat returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice. (bsc#1110850)

This update was imported from the SUSE:SLE-12-SP2:Update update project.

Список пакетов

openSUSE Leap 42.3
tomcat-8.0.53-18.1
tomcat-admin-webapps-8.0.53-18.1
tomcat-docs-webapp-8.0.53-18.1
tomcat-el-3_0-api-8.0.53-18.1
tomcat-embed-8.0.53-18.1
tomcat-javadoc-8.0.53-18.1
tomcat-jsp-2_3-api-8.0.53-18.1
tomcat-jsvc-8.0.53-18.1
tomcat-lib-8.0.53-18.1
tomcat-servlet-3_1-api-8.0.53-18.1
tomcat-webapps-8.0.53-18.1

Описание

When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.


Затронутые продукты
openSUSE Leap 42.3:tomcat-8.0.53-18.1
openSUSE Leap 42.3:tomcat-admin-webapps-8.0.53-18.1
openSUSE Leap 42.3:tomcat-docs-webapp-8.0.53-18.1
openSUSE Leap 42.3:tomcat-el-3_0-api-8.0.53-18.1

Ссылки