SUSE-SU-2015:1337-1

Source
https://www.suse.com/support/update/announcement/2015/suse-su-20151337-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:1337-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2015:1337-1
Upstream
CVE (6)
  • CVE-2012-0022
  • CVE-2012-3544
  • CVE-2013-1976
  • CVE-2014-0227
  • CVE-2014-0230
  • CVE-2014-7810
Related
Published
2013-08-02T13:29:14Z
Modified
2026-02-04T03:53:07Z
Summary
Security update for tomcat6
Details

This update of tomcat6 fixes:

* apache-tomcat-CVE-2012-3544.patch (bnc#831119)
* use chown --no-dereference to prevent symlink attacks on log
  (bnc#822177#c7/prevents CVE-2013-1976)
* Fix tomcat init scripts generating malformed classpath (
  http://youtrack.jetbrains.com/issue/JT-18545
  <http://youtrack.jetbrains.com/issue/JT-18545> ) bnc#804992 (patch
  from m407)
* fix a typo in initscript (bnc#768772 )
* copy all shell scripts (bnc#818948)

Security Issue references:

* CVE-2012-3544
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3544>
* CVE-2013-1976
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1976>
* CVE-2012-0022
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0022>
References

Affected packages