ID

VAR-201201-0259


CVE

CVE-2011-4858


TITLE

Hash table implementations vulnerable to algorithmic complexity attacks

Trust: 0.8

sources: CERT/CC: VU#903934

DESCRIPTION

Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. Some programming language implementations do not sufficiently randomize their hash functions or provide means to limit key collision attacks, which can be leveraged by an unauthenticated attacker to cause a denial-of-service (DoS) condition. Multiple Hitachi COBOL2002 products have security vulnerabilities that allow attackers to take control of target user systems. No detailed vulnerability details are provided at this time. Release Date: 2012-03-27 Last Updated: 2012-03-27 Potential Security Impact: Remote Denial of Service (DoS) Source: Hewlett-Packard Company, HP Software Security Response Team VULNERABILITY SUMMARY Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM) running Apache Tomcat. The vulnerabilities could be exploited remotely to create a Denial of Service (DoS). References: CVE-2012-0022, CVE-2011-4858 SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. HP OpenView Network Node Manager (OV NNM) v7.53 running on HP-UX, Linux, and Solaris. BACKGROUND CVSS 2.0 Base Metrics =========================================================== Reference Base Vector Base Score CVE-2012-0022 (AV:N/AC:L/Au:N/C:N/I:N/A:P) 5.0 CVE-2011-4858 (AV:N/AC:L/Au:N/C:N/I:N/A:P) 5.0 =========================================================== Information on CVSS is documented in HP Customer Notice: HPSN-2008-002 RESOLUTION HP has provided a hotfix to resolve the vulnerability. The SSRT100771 hotfix is available by contacting the normal HP Services support channel. MANUAL ACTIONS: Yes - NonUpdate Install the hotfix for SSRT100771. PRODUCT SPECIFIC INFORMATION HP-UX Software Assistant: HP-UX Software Assistant is an enhanced application that replaces HP-UX Security Patch Check. It analyzes all Security Bulletins issued by HP and lists recommended actions that may apply to a specific HP-UX system. It can also download patches and create a depot automatically. For more information see https://www.hp.com/go/swa The following text is for use by the HP-UX Software Assistant. AFFECTED VERSIONS (for HP-UX) For HP-UX OV NNM 7.53 HP-UX B.11.31 HP-UX B.11.23 (IA) HP-UX B.11.23 (PA) HP-UX B.11.11 ============= OVNNMgr.OVNNM-RUN,fr=B.07.50.00 action: install the hotfix for SSRT100771 END AFFECTED VERSIONS (for HP-UX) HISTORY Version:1 (rev.1) - 27 March 2012 Initial release Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com. Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via Email: http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins Security Bulletin List: A list of HP Security Bulletins, updated periodically, is contained in HP Security Notice HPSN-2011-001: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c02964430 Security Bulletin Archive: A list of recently released Security Bulletins is available here: http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secBullArchive/ Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB. 3C = 3COM 3P = 3rd Party Software GN = HP General Software HF = HP Hardware and Firmware MP = MPE/iX MU = Multi-Platform Software NS = NonStop Servers OV = OpenVMS PI = Printing and Imaging PV = ProCurve ST = Storage Software TU = Tru64 UNIX UX = HP-UX Copyright 2012 Hewlett-Packard Development Company, L.P. Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental,special or consequential damages including downtime cost; lost profits;damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201206-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Apache Tomcat: Multiple vulnerabilities Date: June 24, 2012 Bugs: #272566, #273662, #303719, #320963, #329937, #373987, #374619, #382043, #386213, #396401, #399227 ID: 201206-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities were found in Apache Tomcat, the worst of which allowing to read, modify and overwrite arbitrary files. Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-servers/tomcat *< 5.5.34 *>= 6.0.35 *< 6.0.35 >= 7.0.23 < 7.0.23 Description =========== Multiple vulnerabilities have been discovered in Apache Tomcat. Please review the CVE identifiers referenced below for details. Impact ====== The vulnerabilities allow an attacker to cause a Denial of Service, to hijack a session, to bypass authentication, to inject webscript, to enumerate valid usernames, to read, modify and overwrite arbitrary files, to bypass intended access restrictions, to delete work-directory files, to discover the server's hostname or IP, to bypass read permissions for files or HTTP headers, to read or write files outside of the intended working directory, and to obtain sensitive information by reading a log file. Workaround ========== There is no known workaround at this time. Resolution ========== All Apache Tomcat 6.0.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-servers/tomcat-6.0.35" All Apache Tomcat 7.0.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-servers/tomcat-7.0.23" References ========== [ 1 ] CVE-2008-5515 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5515 [ 2 ] CVE-2009-0033 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0033 [ 3 ] CVE-2009-0580 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0580 [ 4 ] CVE-2009-0781 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0781 [ 5 ] CVE-2009-0783 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0783 [ 6 ] CVE-2009-2693 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2693 [ 7 ] CVE-2009-2901 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2901 [ 8 ] CVE-2009-2902 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2902 [ 9 ] CVE-2010-1157 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1157 [ 10 ] CVE-2010-2227 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2227 [ 11 ] CVE-2010-3718 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3718 [ 12 ] CVE-2010-4172 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4172 [ 13 ] CVE-2010-4312 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4312 [ 14 ] CVE-2011-0013 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0013 [ 15 ] CVE-2011-0534 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0534 [ 16 ] CVE-2011-1088 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1088 [ 17 ] CVE-2011-1183 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1183 [ 18 ] CVE-2011-1184 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1184 [ 19 ] CVE-2011-1419 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1419 [ 20 ] CVE-2011-1475 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1475 [ 21 ] CVE-2011-1582 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1582 [ 22 ] CVE-2011-2204 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2204 [ 23 ] CVE-2011-2481 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2481 [ 24 ] CVE-2011-2526 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2526 [ 25 ] CVE-2011-2729 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2729 [ 26 ] CVE-2011-3190 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3190 [ 27 ] CVE-2011-3375 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3375 [ 28 ] CVE-2011-4858 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4858 [ 29 ] CVE-2011-5062 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5062 [ 30 ] CVE-2011-5063 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5063 [ 31 ] CVE-2011-5064 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5064 [ 32 ] CVE-2012-0022 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0022 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201206-24.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2012 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . A flaw was found in the way JBoss Web handled UTF-8 surrogate pair characters. If JBoss Web was hosting an application with UTF-8 character encoding enabled, or that included user-supplied UTF-8 strings in a response, a remote attacker could use this flaw to cause a denial of service (infinite loop) on the JBoss Web server. These hotfixes also apply to the following products and can be applied to all patch levels: HP NNM iSPI for IP QA HP NNM iSPI for IP Telephony HP NNM SPI for IP Multicast HP NNM SPI for MPLS NNMi Version Operating System Hotfix 9.00 HP-UX, Linux, Solaris, and Windows. HF-NNMi-9.0xP5-JBoss-20130417 9.10 HP-UX, Linux, Solaris, and Windows. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. Users of Tomcat should upgrade to these updated packages, which correct these issues. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/tomcat5-5.5.23-0jpp.31.el5_8.src.rpm i386: tomcat5-debuginfo-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-jsp-2.0-api-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-servlet-2.4-api-5.5.23-0jpp.31.el5_8.i386.rpm x86_64: tomcat5-debuginfo-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-jsp-2.0-api-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-servlet-2.4-api-5.5.23-0jpp.31.el5_8.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/tomcat5-5.5.23-0jpp.31.el5_8.src.rpm i386: tomcat5-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-admin-webapps-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-common-lib-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-debuginfo-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-jasper-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-jasper-javadoc-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-jsp-2.0-api-javadoc-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-server-lib-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-servlet-2.4-api-javadoc-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-webapps-5.5.23-0jpp.31.el5_8.i386.rpm x86_64: tomcat5-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-admin-webapps-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-common-lib-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-debuginfo-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-jasper-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-jasper-javadoc-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-jsp-2.0-api-javadoc-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-server-lib-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-servlet-2.4-api-javadoc-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-webapps-5.5.23-0jpp.31.el5_8.x86_64.rpm Red Hat Enterprise Linux (v. 5 server): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Server/en/os/SRPMS/tomcat5-5.5.23-0jpp.31.el5_8.src.rpm i386: tomcat5-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-admin-webapps-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-common-lib-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-debuginfo-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-jasper-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-jasper-javadoc-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-jsp-2.0-api-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-jsp-2.0-api-javadoc-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-server-lib-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-servlet-2.4-api-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-servlet-2.4-api-javadoc-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-webapps-5.5.23-0jpp.31.el5_8.i386.rpm ia64: tomcat5-5.5.23-0jpp.31.el5_8.ia64.rpm tomcat5-admin-webapps-5.5.23-0jpp.31.el5_8.ia64.rpm tomcat5-common-lib-5.5.23-0jpp.31.el5_8.ia64.rpm tomcat5-debuginfo-5.5.23-0jpp.31.el5_8.ia64.rpm tomcat5-jasper-5.5.23-0jpp.31.el5_8.ia64.rpm tomcat5-jasper-javadoc-5.5.23-0jpp.31.el5_8.ia64.rpm tomcat5-jsp-2.0-api-5.5.23-0jpp.31.el5_8.ia64.rpm tomcat5-jsp-2.0-api-javadoc-5.5.23-0jpp.31.el5_8.ia64.rpm tomcat5-server-lib-5.5.23-0jpp.31.el5_8.ia64.rpm tomcat5-servlet-2.4-api-5.5.23-0jpp.31.el5_8.ia64.rpm tomcat5-servlet-2.4-api-javadoc-5.5.23-0jpp.31.el5_8.ia64.rpm tomcat5-webapps-5.5.23-0jpp.31.el5_8.ia64.rpm ppc: tomcat5-5.5.23-0jpp.31.el5_8.ppc.rpm tomcat5-5.5.23-0jpp.31.el5_8.ppc64.rpm tomcat5-admin-webapps-5.5.23-0jpp.31.el5_8.ppc.rpm tomcat5-common-lib-5.5.23-0jpp.31.el5_8.ppc.rpm tomcat5-debuginfo-5.5.23-0jpp.31.el5_8.ppc.rpm tomcat5-debuginfo-5.5.23-0jpp.31.el5_8.ppc64.rpm tomcat5-jasper-5.5.23-0jpp.31.el5_8.ppc.rpm tomcat5-jasper-javadoc-5.5.23-0jpp.31.el5_8.ppc.rpm tomcat5-jsp-2.0-api-5.5.23-0jpp.31.el5_8.ppc.rpm tomcat5-jsp-2.0-api-javadoc-5.5.23-0jpp.31.el5_8.ppc.rpm tomcat5-server-lib-5.5.23-0jpp.31.el5_8.ppc.rpm tomcat5-servlet-2.4-api-5.5.23-0jpp.31.el5_8.ppc.rpm tomcat5-servlet-2.4-api-javadoc-5.5.23-0jpp.31.el5_8.ppc.rpm tomcat5-webapps-5.5.23-0jpp.31.el5_8.ppc.rpm s390x: tomcat5-5.5.23-0jpp.31.el5_8.s390x.rpm tomcat5-admin-webapps-5.5.23-0jpp.31.el5_8.s390x.rpm tomcat5-common-lib-5.5.23-0jpp.31.el5_8.s390x.rpm tomcat5-debuginfo-5.5.23-0jpp.31.el5_8.s390x.rpm tomcat5-jasper-5.5.23-0jpp.31.el5_8.s390x.rpm tomcat5-jasper-javadoc-5.5.23-0jpp.31.el5_8.s390x.rpm tomcat5-jsp-2.0-api-5.5.23-0jpp.31.el5_8.s390x.rpm tomcat5-jsp-2.0-api-javadoc-5.5.23-0jpp.31.el5_8.s390x.rpm tomcat5-server-lib-5.5.23-0jpp.31.el5_8.s390x.rpm tomcat5-servlet-2.4-api-5.5.23-0jpp.31.el5_8.s390x.rpm tomcat5-servlet-2.4-api-javadoc-5.5.23-0jpp.31.el5_8.s390x.rpm tomcat5-webapps-5.5.23-0jpp.31.el5_8.s390x.rpm x86_64: tomcat5-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-admin-webapps-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-common-lib-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-debuginfo-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-jasper-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-jasper-javadoc-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-jsp-2.0-api-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-jsp-2.0-api-javadoc-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-server-lib-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-servlet-2.4-api-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-servlet-2.4-api-javadoc-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-webapps-5.5.23-0jpp.31.el5_8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: tomcat6 security and bug fix update Advisory ID: RHSA-2012:0681-01 Product: JBoss Enterprise Web Server Advisory URL: https://rhn.redhat.com/errata/RHSA-2012-0681.html Issue date: 2012-05-21 CVE Names: CVE-2011-1184 CVE-2011-2204 CVE-2011-2526 CVE-2011-3190 CVE-2011-3375 CVE-2011-4858 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 CVE-2012-0022 ===================================================================== 1. Summary: An update for the Apache Tomcat 6 component for JBoss Enterprise Web Server 1.0.2 that fixes multiple security issues and three bugs is now available from the Red Hat Customer Portal. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Description: Apache Tomcat is a servlet container. JBoss Enterprise Web Server includes the Tomcat Native library, providing Apache Portable Runtime (APR) support for Tomcat. References in this text to APR refer to the Tomcat Native implementation, not any other apr package. This update fixes the JBPAPP-4873, JBPAPP-6133, and JBPAPP-6852 bugs. It also resolves the following security issues: Multiple flaws weakened the Tomcat HTTP DIGEST authentication implementation, subjecting it to some of the weaknesses of HTTP BASIC authentication, for example, allowing remote attackers to perform session replay attacks. (CVE-2011-1184, CVE-2011-5062, CVE-2011-5063, CVE-2011-5064) A flaw was found in the way the Coyote (org.apache.coyote.ajp.AjpProcessor) and APR (org.apache.coyote.ajp.AjpAprProcessor) Tomcat AJP (Apache JServ Protocol) connectors processed certain POST requests. An attacker could send a specially-crafted request that would cause the connector to treat the message body as a new request. This allows arbitrary AJP messages to be injected, possibly allowing an attacker to bypass a web application's authentication checks and gain access to information they would otherwise be unable to access. The JK (org.apache.jk.server.JkCoyoteHandler) connector is used by default when the APR libraries are not present. The JK connector is not affected by this flaw. (CVE-2011-3190) A flaw in the way Tomcat recycled objects that contain data from user requests (such as IP addresses and HTTP headers) when certain errors occurred. If a user sent a request that caused an error to be logged, Tomcat would return a reply to the next request (which could be sent by a different user) with data from the first user's request, leading to information disclosure. Under certain conditions, a remote attacker could leverage this flaw to hijack sessions. (CVE-2011-3375) The Java hashCode() method implementation was susceptible to predictable hash collisions. This update introduces a limit on the number of parameters processed per request to mitigate this issue. The default limit is 512 for parameters and 128 for headers. These defaults can be changed by setting the org.apache.tomcat.util.http.Parameters.MAX_COUNT and org.apache.tomcat.util.http.MimeHeaders.MAX_COUNT system properties. (CVE-2011-4858) Tomcat did not handle large numbers of parameters and large parameter values efficiently. A remote attacker could make Tomcat use an excessive amount of CPU time by sending an HTTP request containing a large number of parameters or large parameter values. This update introduces limits on the number of parameters and headers processed per request to address this issue. Refer to the CVE-2011-4858 description for information about the org.apache.tomcat.util.http.Parameters.MAX_COUNT and org.apache.tomcat.util.http.MimeHeaders.MAX_COUNT system properties. (CVE-2012-0022) A flaw in the Tomcat MemoryUserDatabase. If a runtime exception occurred when creating a new user with a JMX client, that user's password was logged to Tomcat log files. Note: By default, only administrators have access to such log files. (CVE-2011-2204) A flaw in the way Tomcat handled sendfile request attributes when using the HTTP APR or NIO (Non-Blocking I/O) connector. A malicious web application running on a Tomcat instance could use this flaw to bypass security manager restrictions and gain access to files it would otherwise be unable to access, or possibly terminate the Java Virtual Machine (JVM). The HTTP NIO connector is used by default in JBoss Enterprise Web Server. (CVE-2011-2526) Red Hat would like to thank oCERT for reporting CVE-2011-4858, and the Apache Tomcat project for reporting CVE-2011-2526. oCERT acknowledges Julian Wälde and Alexander Klink as the original reporters of CVE-2011-4858. 3. Solution: All users of JBoss Enterprise Web Server 1.0.2 as provided from the Red Hat Customer Portal are advised to apply this update. The References section of this erratum contains a download link (you must log in to download the update). Before applying the update, back up your existing JBoss Enterprise Web Server installation (including all applications and configuration files). Tomcat must be restarted for this update to take effect. 4. Bugs fixed (http://bugzilla.redhat.com/): 717013 - CVE-2011-2204 tomcat: password disclosure vulnerability 720948 - CVE-2011-2526 tomcat: security manager restrictions bypass 734868 - CVE-2011-3190 tomcat: authentication bypass and information disclosure 741401 - CVE-2011-1184 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 tomcat: Multiple weaknesses in HTTP DIGEST authentication 750521 - CVE-2011-4858 tomcat: hash table collisions CPU usage DoS (oCERT-2011-003) 782624 - CVE-2011-3375 tomcat: information disclosure due to improper response and request object recycling 783359 - CVE-2012-0022 tomcat: large number of parameters DoS 5. References: https://www.redhat.com/security/data/cve/CVE-2011-1184.html https://www.redhat.com/security/data/cve/CVE-2011-2204.html https://www.redhat.com/security/data/cve/CVE-2011-2526.html https://www.redhat.com/security/data/cve/CVE-2011-3190.html https://www.redhat.com/security/data/cve/CVE-2011-3375.html https://www.redhat.com/security/data/cve/CVE-2011-4858.html https://www.redhat.com/security/data/cve/CVE-2011-5062.html https://www.redhat.com/security/data/cve/CVE-2011-5063.html https://www.redhat.com/security/data/cve/CVE-2011-5064.html https://www.redhat.com/security/data/cve/CVE-2012-0022.html https://access.redhat.com/security/updates/classification/#moderate http://tomcat.apache.org/security-6.html https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=webserver&downloadType=securityPatches&version=1.0.2 https://issues.jboss.org/browse/JBPAPP-4873 https://issues.jboss.org/browse/JBPAPP-6133 https://issues.jboss.org/browse/JBPAPP-6852 6. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2012 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFPunlvXlSAg2UNWIIRAvqnAKCFCNODTaq3A180VLq9ptMsBURTcwCgsJls JsG5zbN8j1JMa8din0vPkdw= =zajO -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce . ---------------------------------------------------------------------- Secunia is hiring! Find your next job here: http://secunia.com/company/jobs/ ---------------------------------------------------------------------- TITLE: Hitachi COBOL2002 Products Unspecified Vulnerability SECUNIA ADVISORY ID: SA47612 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/47612/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=47612 RELEASE DATE: 2012-01-20 DISCUSS ADVISORY: http://secunia.com/advisories/47612/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/47612/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=47612 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Hitachi has reported a vulnerability in some COBOL2002 products, which can be exploited by malicious users to compromise a vulnerable system. The vulnerability is caused due to an unspecified error. No further information is currently available. PROVIDED AND/OR DISCOVERED BY: Reported by the vendor. ORIGINAL ADVISORY: http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS12-002/index.html OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 3.06

sources: NVD: CVE-2011-4858 // CERT/CC: VU#903934 // CNVD: CNVD-2012-0341 // VULMON: CVE-2011-4858 // PACKETSTORM: 121037 // PACKETSTORM: 111284 // PACKETSTORM: 114139 // PACKETSTORM: 112907 // PACKETSTORM: 109270 // PACKETSTORM: 122552 // PACKETSTORM: 111782 // PACKETSTORM: 112908 // PACKETSTORM: 108859

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2012-0341

AFFECTED PRODUCTS

vendor:apachemodel:tomcatscope:eqversion:6.0.0

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.8

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.11

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.8

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:5.5.35

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.16

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.24

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.21

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.4

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.11

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.22

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.6

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.14

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.31

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.33

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.10

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.17

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.20

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.19

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.18

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.14

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.3

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.0

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.3

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.5

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.7

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.29

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.12

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.2

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.1

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.34

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.1

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.26

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.9

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.16

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.5

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.19

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.9

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.12

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.15

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.13

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.13

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.7

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.18

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.22

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.32

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.23

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.25

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.10

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.21

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.2

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.28

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.30

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.15

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.4

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.6

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.17

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.27

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.20

Trust: 1.0

vendor:apache tomcatmodel: - scope: - version: -

Trust: 0.8

vendor:microsoftmodel: - scope: - version: -

Trust: 0.8

vendor:oraclemodel: - scope: - version: -

Trust: 0.8

vendor:rubymodel: - scope: - version: -

Trust: 0.8

vendor:the php groupmodel: - scope: - version: -

Trust: 0.8

vendor:hitachimodel:cobol2002 net server suitescope:eqversion:2.x

Trust: 0.6

vendor:hitachimodel:cobol2002 net client suitescope:eqversion:2.x

Trust: 0.6

vendor:hitachimodel:cobol2002 net developerscope:eqversion:2.x

Trust: 0.6

sources: CERT/CC: VU#903934 // CNVD: CNVD-2012-0341 // NVD: CVE-2011-4858

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2011-4858
value: MEDIUM

Trust: 1.0

CARNEGIE MELLON: VU#903934
value: 10.80

Trust: 0.8

VULMON: CVE-2011-4858
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2011-4858
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

sources: CERT/CC: VU#903934 // VULMON: CVE-2011-4858 // NVD: CVE-2011-4858

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.0

sources: NVD: CVE-2011-4858

THREAT TYPE

remote

Trust: 0.3

sources: PACKETSTORM: 109270 // PACKETSTORM: 111782 // PACKETSTORM: 112908

TYPE

arbitrary

Trust: 0.2

sources: PACKETSTORM: 114139 // PACKETSTORM: 122552

EXPLOIT AVAILABILITY

sources: VULMON: CVE-2011-4858

PATCH

title:Patch for Hitachi COBOL2002 product has an unknown vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/8212

Trust: 0.6

title:Red Hat: Moderate: tomcat6 security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120475 - Security Advisory

Trust: 0.1

title:Red Hat: Moderate: tomcat5 security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120474 - Security Advisory

Trust: 0.1

title:Red Hat: Important: jbossweb security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120074 - Security Advisory

Trust: 0.1

title:Red Hat: Important: jbossweb security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120076 - Security Advisory

Trust: 0.1

title:Ubuntu Security Notice: tomcat6 vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-1359-1

Trust: 0.1

title:Red Hat: Moderate: tomcat5 security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120680 - Security Advisory

Trust: 0.1

title:Red Hat: Moderate: tomcat6 security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120682 - Security Advisory

Trust: 0.1

title: - url:https://github.com/Live-Hack-CVE/CVE-2011-4084

Trust: 0.1

sources: CNVD: CNVD-2012-0341 // VULMON: CVE-2011-4858

EXTERNAL IDS

db:OCERTid:OCERT-2011-003

Trust: 1.9

db:CERT/CCid:VU#903934

Trust: 1.9

db:NVDid:CVE-2011-4858

Trust: 1.9

db:SECUNIAid:48791

Trust: 1.1

db:SECUNIAid:48790

Trust: 1.1

db:SECUNIAid:48549

Trust: 1.1

db:SECUNIAid:54971

Trust: 1.1

db:SECUNIAid:55115

Trust: 1.1

db:BIDid:51200

Trust: 1.1

db:SECUNIAid:47612

Trust: 0.8

db:CNVDid:CNVD-2012-0341

Trust: 0.6

db:EXPLOIT-DBid:2012

Trust: 0.1

db:VULMONid:CVE-2011-4858

Trust: 0.1

db:PACKETSTORMid:121037

Trust: 0.1

db:PACKETSTORMid:111284

Trust: 0.1

db:PACKETSTORMid:114139

Trust: 0.1

db:PACKETSTORMid:112907

Trust: 0.1

db:PACKETSTORMid:109270

Trust: 0.1

db:PACKETSTORMid:122552

Trust: 0.1

db:PACKETSTORMid:111782

Trust: 0.1

db:PACKETSTORMid:112908

Trust: 0.1

db:HITACHIid:HS12-002

Trust: 0.1

db:PACKETSTORMid:108859

Trust: 0.1

sources: CERT/CC: VU#903934 // CNVD: CNVD-2012-0341 // VULMON: CVE-2011-4858 // PACKETSTORM: 121037 // PACKETSTORM: 111284 // PACKETSTORM: 114139 // PACKETSTORM: 112907 // PACKETSTORM: 109270 // PACKETSTORM: 122552 // PACKETSTORM: 111782 // PACKETSTORM: 112908 // PACKETSTORM: 108859 // NVD: CVE-2011-4858

REFERENCES

url:http://www.ocert.org/advisories/ocert-2011-003.html

Trust: 1.9

url:http://www.nruns.com/_downloads/advisory28122011.pdf

Trust: 1.9

url:http://rhn.redhat.com/errata/rhsa-2012-0077.html

Trust: 1.2

url:https://bugzilla.redhat.com/show_bug.cgi?id=750521

Trust: 1.1

url:http://tomcat.apache.org/tomcat-7.0-doc/changelog.html

Trust: 1.1

url:http://www.kb.cert.org/vuls/id/903934

Trust: 1.1

url:https://github.com/firefart/hashcollision-dos-poc/blob/master/hashtablepoc.py

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=132871655717248&w=2

Trust: 1.1

url:http://www.debian.org/security/2012/dsa-2401

Trust: 1.1

url:http://secunia.com/advisories/48791

Trust: 1.1

url:http://secunia.com/advisories/48790

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=136485229118404&w=2

Trust: 1.1

url:http://secunia.com/advisories/54971

Trust: 1.1

url:http://secunia.com/advisories/55115

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0089.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0406.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0074.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0075.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0325.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0076.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0078.html

Trust: 1.1

url:http://www.securityfocus.com/bid/51200

Trust: 1.1

url:https://oval.cisecurity.org/repository/search/definition/oval%3aorg.mitre.oval%3adef%3a18886

Trust: 1.1

url:http://secunia.com/advisories/48549

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=133294394108746&w=2

Trust: 1.1

url:http://mail-archives.apache.org/mod_mbox/tomcat-announce/201112.mbox/%3c4efb9800.5010106%40apache.org%3e

Trust: 1.0

url:http://www.cs.rice.edu/~scrosby/hash/crosbywallach_usenixsec2003.pdf

Trust: 0.8

url:http://technet.microsoft.com/en-us/security/bulletin/ms11-100.mspx

Trust: 0.8

url:http://blogs.technet.com/b/srd/archive/2011/12/27/more-information-about-the-december-2011-asp-net-vulnerability.aspx

Trust: 0.8

url:http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-talk/391606

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2011-4858

Trust: 0.8

url:http://secunia.com/advisories/47612/

Trust: 0.7

url:https://nvd.nist.gov/vuln/detail/cve-2012-0022

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2011-2526

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2011-1184

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2011-2204

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2011-3190

Trust: 0.4

url:https://www.redhat.com/security/data/cve/cve-2012-0022.html

Trust: 0.4

url:https://www.redhat.com/security/data/cve/cve-2011-4858.html

Trust: 0.4

url:https://access.redhat.com/security/team/contact/

Trust: 0.4

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.4

url:http://bugzilla.redhat.com/):

Trust: 0.4

url:http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins

Trust: 0.3

url:https://www.redhat.com/security/data/cve/cve-2011-5063.html

Trust: 0.3

url:https://www.redhat.com/security/data/cve/cve-2011-2526.html

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2011-5063

Trust: 0.3

url:https://www.redhat.com/security/data/cve/cve-2011-5064.html

Trust: 0.3

url:https://www.redhat.com/security/data/cve/cve-2011-1184.html

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2011-5064

Trust: 0.3

url:https://access.redhat.com/security/updates/classification/#moderate

Trust: 0.3

url:https://www.redhat.com/security/data/cve/cve-2011-5062.html

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2011-5062

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2009-0033

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2009-2902

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2010-3718

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2009-0580

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2009-2693

Trust: 0.2

url:http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secbullarchive/

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2009-0781

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2010-2227

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2008-5515

Trust: 0.2

url:https://www.hp.com/go/swa

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2009-0783

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2011-0013

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2010-1157

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2011-2729

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2011-3375

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2011-2204.html

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2011-3190.html

Trust: 0.2

url:https://issues.jboss.org/browse/jbpapp-6133

Trust: 0.2

url:https://issues.jboss.org/browse/jbpapp-4873

Trust: 0.2

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?product=webserver&downloadtype=securitypatches&version=1.0.2

Trust: 0.2

url:http://tomcat.apache.org/security-5.html

Trust: 0.2

url:https://cwe.mitre.org/data/definitions/399.html

Trust: 0.1

url:http://mail-archives.apache.org/mod_mbox/tomcat-announce/201112.mbox/%3c4efb9800.5010106@apache.org%3e

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2012:0475

Trust: 0.1

url:https://github.com/live-hack-cve/cve-2011-4084

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://usn.ubuntu.com/1359-1/

Trust: 0.1

url:https://www.exploit-db.com/exploits/2012/

Trust: 0.1

url:http://tools.cisco.com/security/center/viewalert.x?alertid=24901

Trust: 0.1

url:https://h20392.www2.hp.com/portal

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-3548

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4476

Trust: 0.1

url:https://h20566.www2.hp.com/portal/site/hpsc/public/kb/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5885

Trust: 0.1

url:https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docdisplay/?docid=emr_na-c02964430

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-0783

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-0033

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-0781

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2729

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-2902

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-5062

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0534

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1183

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-3718

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1475

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0534

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0013

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-5063

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1582

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-4172

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-5064

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-4312

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1475

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1088

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-0580

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-2901

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2526

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1183

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1184

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2204

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-0022

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-2693

Trust: 0.1

url:http://security.gentoo.org/

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-1157

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4172

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1088

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2481

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4312

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-4858

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-2227

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2481

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2008-5515

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-2901

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-3190

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1419

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-3375

Trust: 0.1

url:http://security.gentoo.org/glsa/glsa-201206-24.xml

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1582

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1419

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0679.html

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2011-4610.html

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-4610

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?product=enterpriseweb.platform&downloadtype=securitypatches&version=5.1.2

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2007-5333

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-0738

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-3554

Trust: 0.1

url:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/

Trust: 0.1

url:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/secbullarchive/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-1429

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1483

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-1428

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2196

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3546

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-4605

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0474.html

Trust: 0.1

url:https://access.redhat.com/kb/docs/doc-11259

Trust: 0.1

url:https://access.redhat.com/security/team/key/#package

Trust: 0.1

url:https://issues.jboss.org/browse/jbpapp-6852

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2011-3375.html

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0681.html

Trust: 0.1

url:http://tomcat.apache.org/security-6.html

Trust: 0.1

url:http://www.hitachi.co.jp/prod/comp/soft1/global/security/info/vuls/hs12-002/index.html

Trust: 0.1

url:http://secunia.com/company/jobs/

Trust: 0.1

url:http://secunia.com/vulnerability_intelligence/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/47612/#comments

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=47612

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

sources: CERT/CC: VU#903934 // CNVD: CNVD-2012-0341 // VULMON: CVE-2011-4858 // PACKETSTORM: 121037 // PACKETSTORM: 111284 // PACKETSTORM: 114139 // PACKETSTORM: 112907 // PACKETSTORM: 109270 // PACKETSTORM: 122552 // PACKETSTORM: 111782 // PACKETSTORM: 112908 // PACKETSTORM: 108859 // NVD: CVE-2011-4858

CREDITS

Red Hat

Trust: 0.4

sources: PACKETSTORM: 112907 // PACKETSTORM: 109270 // PACKETSTORM: 111782 // PACKETSTORM: 112908

SOURCES

db:CERT/CCid:VU#903934
db:CNVDid:CNVD-2012-0341
db:VULMONid:CVE-2011-4858
db:PACKETSTORMid:121037
db:PACKETSTORMid:111284
db:PACKETSTORMid:114139
db:PACKETSTORMid:112907
db:PACKETSTORMid:109270
db:PACKETSTORMid:122552
db:PACKETSTORMid:111782
db:PACKETSTORMid:112908
db:PACKETSTORMid:108859
db:NVDid:CVE-2011-4858

LAST UPDATE DATE

2026-04-17T21:02:39.425000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#903934date:2016-02-15T00:00:00
db:CNVDid:CNVD-2012-0341date:2012-02-01T00:00:00
db:VULMONid:CVE-2011-4858date:2018-01-09T00:00:00
db:NVDid:CVE-2011-4858date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CERT/CCid:VU#903934date:2011-12-28T00:00:00
db:CNVDid:CNVD-2012-0341date:2012-02-01T00:00:00
db:VULMONid:CVE-2011-4858date:2012-01-05T00:00:00
db:PACKETSTORMid:121037date:2013-04-01T15:55:00
db:PACKETSTORMid:111284date:2012-03-29T02:50:44
db:PACKETSTORMid:114139date:2012-06-24T23:54:31
db:PACKETSTORMid:112907date:2012-05-22T00:22:52
db:PACKETSTORMid:109270date:2012-02-01T02:54:24
db:PACKETSTORMid:122552date:2013-07-25T18:22:00
db:PACKETSTORMid:111782date:2012-04-12T03:11:30
db:PACKETSTORMid:112908date:2012-05-22T00:23:56
db:PACKETSTORMid:108859date:2012-01-20T08:20:00
db:NVDid:CVE-2011-4858date:2012-01-05T19:55:01.033