~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2011-2526

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2011-07-14
2
 
Candidate: CVE-2011-2526
3
 
PublicDate: 2011-07-14
4
 
References:
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2526
6
 
 https://usn.ubuntu.com/usn/usn-1252-1
7
 
Description:
8
 
 Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before
9
 
 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector,
10
 
 does not validate certain request attributes, which allows local users to
11
 
 bypass intended file access restrictions or cause a denial of service
12
 
 (infinite loop or JVM crash) by leveraging an untrusted web application.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
Bugs:
16
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=634992
17
 
Priority: low
18
 
Discovered-by:
19
 
Assigned-to: mdeslaur
20
 
 
21
 
Patches_tomcat5.5:
22
 
 upstream: http://svn.apache.org/viewvc?view=revision&revision=1158244
23
 
upstream_tomcat5.5: released (5.5.34)
24
 
hardy_tomcat5.5: ignored (reached end-of-life)
25
 
lucid_tomcat5.5: DNE
26
 
maverick_tomcat5.5: DNE
27
 
natty_tomcat5.5: DNE
28
 
oneiric_tomcat5.5: DNE
29
 
devel_tomcat5.5: DNE
30
 
 
31
 
Patches_tomcat6:
32
 
 upstream: http://svn.apache.org/viewvc?view=revision&revision=1146703
33
 
upstream_tomcat6: released (6.0.33)
34
 
hardy_tomcat6: DNE
35
 
lucid_tomcat6: released (6.0.24-2ubuntu1.9)
36
 
maverick_tomcat6: released (6.0.28-2ubuntu1.5)
37
 
natty_tomcat6: released (6.0.28-10ubuntu2.2)
38
 
oneiric_tomcat6: released (6.0.32-5ubuntu1.1)
39
 
devel_tomcat6: released (6.0.32-6ubuntu1)
40
 
 
41
 
Patches_tomcat7:
42
 
 upstream: http://svn.apache.org/viewvc?view=revision&revision=1146005
43
 
 upstream: http://svn.apache.org/viewvc?view=revision&revision=1145694
44
 
 upstream: http://svn.apache.org/viewvc?view=revision&revision=1145571
45
 
 upstream: http://svn.apache.org/viewvc?view=revision&revision=1145489
46
 
 upstream: http://svn.apache.org/viewvc?view=revision&revision=1145383
47
 
upstream_tomcat7: released (7.0.19)
48
 
hardy_tomcat7: DNE
49
 
lucid_tomcat7: DNE
50
 
maverick_tomcat7: DNE
51
 
natty_tomcat7: DNE
52
 
oneiric_tomcat7: not-affected (7.0.21-1)
53
 
devel_tomcat7: not-affected (7.0.21-1)