~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to ignored/CVE-2010-1157

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2010-1157
2
 
PublicDate: 2010-04-23
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1157
5
 
 http://tomcat.apache.org/security-6.html
6
 
 http://tomcat.apache.org/security-5.html
7
 
Description:
8
 
 Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow
9
 
 remote attackers to discover the server's hostname or IP address by sending
10
 
 a request for a resource that requires (1) BASIC or (2) DIGEST
11
 
 authentication, and then reading the realm field in the WWW-Authenticate
12
 
 header in the reply.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
 mdeslaur> upstream patch changes the default realm name. This may have
16
 
 mdeslaur> too great an impact of existing installations to be worthwhile
17
 
 mdeslaur> backporting. Ignoring.
18
 
Bugs:
19
 
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-1157
20
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=587447
21
 
Priority: negligible
22
 
Discovered-by:
23
 
Assigned-to:
24
 
 
25
 
Patches_tomcat5:
26
 
upstream_tomcat5: needed
27
 
dapper_tomcat5: ignored (reached end-of-life)
28
 
hardy_tomcat5: DNE
29
 
intrepid_tomcat5: DNE
30
 
jaunty_tomcat5: DNE
31
 
karmic_tomcat5: DNE
32
 
lucid_tomcat5: DNE
33
 
devel_tomcat5: DNE
34
 
 
35
 
Patches_tomcat5.5:
36
 
 upstream: http://svn.apache.org/viewvc?view=revision&revision=936541
37
 
upstream_tomcat5.5: released (5.5.30)
38
 
dapper_tomcat5.5: DNE
39
 
hardy_tomcat5.5: ignored
40
 
intrepid_tomcat5.5: needed (reached end-of-life)
41
 
jaunty_tomcat5.5: ignored
42
 
karmic_tomcat5.5: DNE
43
 
lucid_tomcat5.5: DNE
44
 
devel_tomcat5.5: DNE
45
 
 
46
 
Patches_tomcat6:
47
 
 upstream: http://svn.apache.org/viewvc?view=revision&revision=936540
48
 
upstream_tomcat6: released (6.0.28)
49
 
dapper_tomcat6: DNE
50
 
hardy_tomcat6: DNE
51
 
intrepid_tomcat6: needed (reached end-of-life)
52
 
jaunty_tomcat6: ignored
53
 
karmic_tomcat6: ignored
54
 
lucid_tomcat6: ignored
55
 
devel_tomcat6: not-affected (6.0.28-2)