Bug 706382 (CVE-2011-2526) - VUL-0: CVE-2011-2526: tomcat information leak and DoS
Summary: VUL-0: CVE-2011-2526: tomcat information leak and DoS
Status: RESOLVED FIXED
Alias: CVE-2011-2526
Product: SUSE Security Incidents
Classification: Novell Products
Component: General (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:11.3:42670 maint:relea...
Keywords:
Depends on:
Blocks:
 
Reported: 2011-07-18 08:30 UTC by Ludwig Nussel
Modified: 2014-07-17 09:34 UTC (History)
1 user (show)

See Also:
Found By: Other
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ludwig Nussel 2011-07-18 08:30:30 UTC
Your friendly security team received the following report via mitre.
Please respond ASAP.
The issue is public.

-------8<-------
======================================================
Name: CVE-2011-2526

Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web application.


Reference: CONFIRM: https://bugzilla.redhat.com/show_bug.cgi?id=720948
Reference: CONFIRM: http://svn.apache.org/viewvc?view=revision&revision=1146005
Reference: CONFIRM: http://svn.apache.org/viewvc?view=revision&revision=1145694
Reference: CONFIRM: http://svn.apache.org/viewvc?view=revision&revision=1145571
Reference: CONFIRM: http://svn.apache.org/viewvc?view=revision&revision=1145383
Reference: BID: http://www.securityfocus.com/bid/48667
Reference: CONFIRM: http://tomcat.apache.org/security-7.html
Reference: CONFIRM: http://tomcat.apache.org/security-6.html
Reference: CONFIRM: http://tomcat.apache.org/security-5.html
Comment 3 Thomas Biege 2011-08-12 16:35:23 UTC
please ignore, just adjusting priority
Comment 4 Michal Vyskocil 2011-08-15 13:41:47 UTC
submitted a fix to

sles9:  N/A - affected files are not in tomcat 5.019 used in sles9
sles10: 14193
sles11: 14194

11.3:   78887
11.4:   78888
Comment 5 Bernhard Wiedemann 2011-08-15 14:00:17 UTC
This is an autogenerated message for OBS integration:
This bug (706382) was mentioned in
https://build.opensuse.org/request/show/78887 11.3 / tomcat6
https://build.opensuse.org/request/show/78888 11.4 / tomcat6
Comment 6 Swamp Workflow Management 2011-08-31 11:25:30 UTC
Update released for: tomcat6, tomcat6-admin-webapps, tomcat6-docs-webapp, tomcat6-el-1_0-api, tomcat6-javadoc, tomcat6-jsp-2_1-api, tomcat6-lib, tomcat6-servlet-2_5-api, tomcat6-webapps
Products:
openSUSE 11.3 (i586)
openSUSE 11.4 (i586)
Comment 7 Swamp Workflow Management 2011-09-01 15:52:02 UTC
Update released for: tomcat5, tomcat5-admin-webapps, tomcat5-webapps
Products:
SLE-SAP-APL 10-SP3 (x86_64)
SLE-SDK 10-SP3 (i386, ia64, ppc, s390x, x86_64)
SLE-SERVER 10-SP3 (i386, ia64, ppc, s390x, x86_64)
SLE-SERVER 10-SP3-TERADATA (x86_64)
Comment 8 Swamp Workflow Management 2011-09-01 17:22:33 UTC
Update released for: tomcat5, tomcat5-admin-webapps, tomcat5-webapps
Products:
SLE-SDK 10-SP4 (i386, ia64, ppc, s390x, x86_64)
SLE-SERVER 10-SP4 (i386, ia64, ppc, s390x, x86_64)
Comment 9 Swamp Workflow Management 2011-09-02 05:27:35 UTC
Update released for: tomcat6, tomcat6-admin-webapps, tomcat6-docs-webapp, tomcat6-javadoc, tomcat6-jsp-2_1-api, tomcat6-lib, tomcat6-servlet-2_5-api, tomcat6-webapps
Products:
SLE-SDK 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SUSE-MANAGER 1.2 (x86_64)
Comment 10 Bernhard Wiedemann 2011-09-06 04:00:18 UTC
This is an autogenerated message for OBS integration:
This bug (706382) was mentioned in
https://build.opensuse.org/request/show/81045 Evergreen:11.2 / tomcat6
Comment 11 Bernhard Wiedemann 2011-09-09 05:00:23 UTC
This is an autogenerated message for OBS integration:
This bug (706382) was mentioned in
https://build.opensuse.org/request/show/81630 Evergreen:11.1 / tomcat6
Comment 12 Ludwig Nussel 2011-09-16 13:02:35 UTC
done already
Comment 13 Bernhard Wiedemann 2011-10-19 11:00:21 UTC
This is an autogenerated message for OBS integration:
This bug (706382) was mentioned in
https://build.opensuse.org/request/show/88690 Evergreen:11.1 / tomcat6