Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-2526

Опубликовано: 14 июл. 2011
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.4

Описание

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web application.

РелизСтатусПримечание
devel

DNE

hardy

ignored

end of life
lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

upstream

released

5.5.34

Показывать по

РелизСтатусПримечание
devel

released

6.0.32-6ubuntu1
hardy

DNE

lucid

released

6.0.24-2ubuntu1.9
maverick

released

6.0.28-2ubuntu1.5
natty

released

6.0.28-10ubuntu2.2
oneiric

released

6.0.32-5ubuntu1.1
upstream

released

6.0.33

Показывать по

РелизСтатусПримечание
devel

not-affected

7.0.21-1
hardy

DNE

lucid

DNE

maverick

DNE

natty

DNE

oneiric

not-affected

7.0.21-1
upstream

released

7.0.19

Показывать по

EPSS

Процентиль: 34%
0.0013
Низкий

4.4 Medium

CVSS2

Связанные уязвимости

redhat
почти 14 лет назад

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web application.

nvd
почти 14 лет назад

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web application.

debian
почти 14 лет назад

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7 ...

github
около 3 лет назад

Improper Input Validation in Apache Tomcat

oracle-oval
больше 13 лет назад

ELSA-2011-1780: tomcat6 security and bug fix update (MODERATE)

EPSS

Процентиль: 34%
0.0013
Низкий

4.4 Medium

CVSS2

Уязвимость CVE-2011-2526