Ubuntu Security Notice (C) 2014-2016 Canonical, Inc. / NASL script (C) 2014-2016 Tenable Network Security, Inc.
The remote Ubuntu host is missing one or more security-related
David Jorm discovered that Tomcat incorrectly handled certain requests
submitted using chunked transfer encoding. A remote attacker could use
this flaw to cause the Tomcat server to consume resources, resulting
in a denial of service. (CVE-2014-0075)
It was discovered that Tomcat did not properly restrict XSLT
stylesheets. An attacker could use this issue with a crafted web
application to bypass security-manager restrictions and read arbitrary
It was discovered that Tomcat incorrectly handled certain
Content-Length headers. A remote attacker could use this flaw in
configurations where Tomcat is behind a reverse proxy to perform HTTP
request smuggling attacks. (CVE-2014-0099).
Note that Tenable Network Security has extracted the preceding
description block directly from the Ubuntu security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.
Update the affected libtomcat6-java and / or libtomcat7-java packages.
Risk factor :
Medium / CVSS Base Score : 5.0
CVSS Temporal Score : 4.3
Public Exploit Available : false