Ubuntu Security Notice (C) 2013-2014 Canonical, Inc. / NASL script (C) 2013-2014 Tenable Network Security, Inc.
The remote Ubuntu host is missing one or more security-related patches.
It was discovered that Tomcat incorrectly performed certain security
constraint checks in the FORM authenticator. A remote attacker could
possibly use this flaw with a specially crafted URI to bypass security
constraint checks. This issue only affected Ubuntu 10.04 LTS, Ubuntu
11.10 and Ubuntu 12.04 LTS. (CVE-2012-3546)
It was discovered that Tomcat incorrectly handled requests that lack a
session identifier. A remote attacker could possibly use this flaw to
bypass the cross-site request forgery protection. (CVE-2012-4431)
It was discovered that Tomcat incorrectly handled sendfile and HTTPS
when the NIO connector is used. A remote attacker could use this flaw
to cause Tomcat to stop responsing, resulting in a denial of service.
This issue only affected Ubuntu 10.04 LTS, Ubuntu 11.10 and Ubuntu
12.04 LTS. (CVE-2012-4534).
Update the affected libtomcat6-java and / or libtomcat7-java packages.
Risk factor :
Medium / CVSS Base Score : 4.3
Family: Ubuntu Local Security Checks
Nessus Plugin ID: 63535 ()
CVE ID: CVE-2012-3546CVE-2012-4431CVE-2012-4534
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.