Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in Tomcat
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in Tomcat
ID: USN-4251-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS
Datum: Mo, 27. Januar 2020, 20:37
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17563
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12418
Applikationen: Apache Tomcat

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============5317692763858884287==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="OF9ZDeQBUwPppJxSCdgdIt2YvIQjpbLEm"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--OF9ZDeQBUwPppJxSCdgdIt2YvIQjpbLEm
Content-Type: multipart/mixed;
boundary="QnglDvMtn0AErxHMZRgzc1ION9dOstqSC"

--QnglDvMtn0AErxHMZRgzc1ION9dOstqSC
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4251-1
January 27, 2020

tomcat8 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in Tomcat.

Software Description:
- tomcat8: Servlet and JSP engine

Details:

It was discovered that Tomcat incorrectly handled the RMI registry when
configured with the JMX Remote Lifecycle Listener. A local attacker could
possibly use this issue to obtain credentials and gain complete control
over the Tomcat instance. (CVE-2019-12418)

It was discovered that Tomcat incorrectly handled FORM authentication. A
remote attacker could possibly use this issue to perform a session fixation
attack. (CVE-2019-17563)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
libtomcat8-java 8.0.32-1ubuntu1.11
tomcat8 8.0.32-1ubuntu1.11

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4251-1
CVE-2019-12418, CVE-2019-17563

Package Information:
https://launchpad.net/ubuntu/+source/tomcat8/8.0.32-1ubuntu1.11


--QnglDvMtn0AErxHMZRgzc1ION9dOstqSC--

--OF9ZDeQBUwPppJxSCdgdIt2YvIQjpbLEm
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl4vDiEACgkQZWnYVadE
vpPbiw/8CqfVrKihzOV3NyJ0x+Af0BIHkrWpbHAcwWe2nZdQzAqqXXlPSgKZiB28
/41FHb/btwtOEXbzAZMIrJFkCyEi9em9EsWNSxrcUMLZX3W9Z/owdmybUwMUovXz
hRhJvEoxycTdLL/k9p0BqIQWXFQS8rGzdG00o6S3fJkgfYS4OaCjRDMVefT5y8Or
wAt/8414FIzKJZ6VtrhLM3/GFSURlOEh/mbVCNCHa5GCONT9smJfxXkaaUC9A/sM
t8L2OxPYUeKSsJwc6E6dM/+I5PsE3uOCRQ++c24MeiP3kRZKGJASDd/mHpZnZFFf
kBwcGRxGVtvIfhZtPg+hJkrU3JjxIfrO67PcjbNrAjSRff7l5FxKfV/yA+DAf00D
deFUtwJ4CVOLezPgwsmxM7N3qmLQvxbVNt5icqSLa5JpCRrIcCRAhOYg+gLZ4t5U
3x7tGCcvPTERDial6FbWpIR9ivPC5cXYg+Y3uQ2lChVFDydwpzapULsKzsNY3t7h
LFJGCTMMaqUdSEGzSXqEakq/Nn0NQyFYQ9po524yh4flB5qDFfrkKX6UpBhl7gJ8
bNk0+ZXIwTHuO3mW6XN+mF3PkkX5/njdJWsKBsVYRR8hc1sZDt+CiANnEzYW2DS/
6GwyxtMr68cGMfhXmZcfI9z49SqmUF+AY7C8CSDyuFx+Vp9z+qw=
=qzOd
-----END PGP SIGNATURE-----

--OF9ZDeQBUwPppJxSCdgdIt2YvIQjpbLEm--


--===============5317692763858884287==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============5317692763858884287==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung