UBUNTU-CVE-2014-0119

Source
https://ubuntu.com/security/CVE-2014-0119
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-0119.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2014-0119
Upstream
  • CVE-2014-0119
Downstream
Related
Published
2014-05-31T00:00:00Z
Modified
2026-02-04T03:13:32.756552Z
Severity
  • Ubuntu - low
Summary
[none]
Details

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

References

Affected packages

Ubuntu:14.04:LTS / tomcat6

Package

Name
tomcat6
Purl
pkg:deb/ubuntu/tomcat6@6.0.39-1ubuntu0.1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.0.39-1ubuntu0.1

Affected versions

6.*
6.0.37-1
6.0.39-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "6.0.39-1ubuntu0.1",
            "binary_name": "libservlet2.4-java"
        },
        {
            "binary_version": "6.0.39-1ubuntu0.1",
            "binary_name": "libservlet2.5-java"
        },
        {
            "binary_version": "6.0.39-1ubuntu0.1",
            "binary_name": "libtomcat6-java"
        },
        {
            "binary_version": "6.0.39-1ubuntu0.1",
            "binary_name": "tomcat6"
        },
        {
            "binary_version": "6.0.39-1ubuntu0.1",
            "binary_name": "tomcat6-admin"
        },
        {
            "binary_version": "6.0.39-1ubuntu0.1",
            "binary_name": "tomcat6-common"
        },
        {
            "binary_version": "6.0.39-1ubuntu0.1",
            "binary_name": "tomcat6-docs"
        },
        {
            "binary_version": "6.0.39-1ubuntu0.1",
            "binary_name": "tomcat6-examples"
        },
        {
            "binary_version": "6.0.39-1ubuntu0.1",
            "binary_name": "tomcat6-extras"
        },
        {
            "binary_version": "6.0.39-1ubuntu0.1",
            "binary_name": "tomcat6-user"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-0119.json"

Ubuntu:14.04:LTS / tomcat7

Package

Name
tomcat7
Purl
pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.3?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.0.52-1ubuntu0.3

Affected versions

7.*
7.0.42-1
7.0.47-1
7.0.50-1
7.0.52-1
7.0.52-1ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "7.0.52-1ubuntu0.3",
            "binary_name": "libservlet3.0-java"
        },
        {
            "binary_version": "7.0.52-1ubuntu0.3",
            "binary_name": "libtomcat7-java"
        },
        {
            "binary_version": "7.0.52-1ubuntu0.3",
            "binary_name": "tomcat7"
        },
        {
            "binary_version": "7.0.52-1ubuntu0.3",
            "binary_name": "tomcat7-admin"
        },
        {
            "binary_version": "7.0.52-1ubuntu0.3",
            "binary_name": "tomcat7-common"
        },
        {
            "binary_version": "7.0.52-1ubuntu0.3",
            "binary_name": "tomcat7-docs"
        },
        {
            "binary_version": "7.0.52-1ubuntu0.3",
            "binary_name": "tomcat7-examples"
        },
        {
            "binary_version": "7.0.52-1ubuntu0.3",
            "binary_name": "tomcat7-user"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-0119.json"