SUSE-SU-2017:3059-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:3059-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2017:3059-1
Related
Published
2017-11-23T16:16:52Z
Modified
2017-11-23T16:16:52Z
Summary
Security update for tomcat
Details

Apache Tomcat was updated to 7.0.82 adding features, fixing bugs and security issues.

This is another bugfix release, for full details see:

https://tomcat.apache.org/tomcat-7.0-doc/changelog.html

Fixed security issues:

  • CVE-2017-5664: A problem in handling error pages was fixed, to avoid potential file overwrites during error page handling. (bsc#1042910).
  • CVE-2017-7674: A CORS Filter issue could lead to client and server side cache poisoning (bsc#1053352)
  • CVE-2017-12617: A remote code execution possibility via JSP Upload was fixed (bsc#1059554)
  • CVE-2017-12616: An information disclosure when using VirtualDirContext was fixed (bsc#1059551)
  • CVE-2017-12615: A Remote Code Execution via JSP Upload was fixed (bsc#1059554)

Non-security issues fixed:

  • Fix tomcat-digest classpath error (bsc#977410)
References

Affected packages

SUSE:Linux Enterprise Server 12-LTSS / tomcat

Package

Name
tomcat
Purl
purl:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.0.82-7.16.1

Ecosystem specific

{
    "binaries": [
        {
            "tomcat-lib": "7.0.82-7.16.1",
            "tomcat-servlet-3_0-api": "7.0.82-7.16.1",
            "tomcat-jsp-2_2-api": "7.0.82-7.16.1",
            "tomcat-webapps": "7.0.82-7.16.1",
            "tomcat-docs-webapp": "7.0.82-7.16.1",
            "tomcat-el-2_2-api": "7.0.82-7.16.1",
            "tomcat": "7.0.82-7.16.1",
            "tomcat-admin-webapps": "7.0.82-7.16.1",
            "tomcat-javadoc": "7.0.82-7.16.1"
        }
    ]
}