Oracle Solaris Third-Party Patch Update : tomcat (multiple_vulnerabilities_in_tomcat)

Medium Nessus Plugin ID 80792


The remote Solaris system is missing a security patch for third-party software.


The remote Solaris system is missing necessary patches to address security updates :

- Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data. (CVE-2012-3544)

- java/org/apache/catalina/authenticator/FormAuthenticator .java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.


Upgrade to Solaris

See Also

Plugin Details

Severity: Medium

ID: 80792

File Name: solaris11_tomcat_20140401_2.nasl

Version: $Revision: 1.2 $

Type: local

Published: 2015/01/19

Modified: 2016/01/14

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/o:oracle:solaris:11.1, p-cpe:/a:oracle:solaris:tomcat

Required KB Items: Host/local_checks_enabled, Host/Solaris11/release, Host/Solaris11/pkg-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/04/01

Reference Information

CVE: CVE-2012-3544, CVE-2013-2067