ID

VAR-201201-0259


CVE

CVE-2011-4858


TITLE

Hash table implementations vulnerable to algorithmic complexity attacks

Trust: 0.8

sources: CERT/CC: VU#903934

DESCRIPTION

Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. Some programming language implementations do not sufficiently randomize their hash functions or provide means to limit key collision attacks, which can be leveraged by an unauthenticated attacker to cause a denial-of-service (DoS) condition. Multiple Hitachi COBOL2002 products have security vulnerabilities that allow attackers to take control of target user systems. No detailed vulnerability details are provided at this time. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201206-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Apache Tomcat: Multiple vulnerabilities Date: June 24, 2012 Bugs: #272566, #273662, #303719, #320963, #329937, #373987, #374619, #382043, #386213, #396401, #399227 ID: 201206-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities were found in Apache Tomcat, the worst of which allowing to read, modify and overwrite arbitrary files. Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-servers/tomcat *< 5.5.34 *>= 6.0.35 *< 6.0.35 >= 7.0.23 < 7.0.23 Description =========== Multiple vulnerabilities have been discovered in Apache Tomcat. Please review the CVE identifiers referenced below for details. Impact ====== The vulnerabilities allow an attacker to cause a Denial of Service, to hijack a session, to bypass authentication, to inject webscript, to enumerate valid usernames, to read, modify and overwrite arbitrary files, to bypass intended access restrictions, to delete work-directory files, to discover the server's hostname or IP, to bypass read permissions for files or HTTP headers, to read or write files outside of the intended working directory, and to obtain sensitive information by reading a log file. Workaround ========== There is no known workaround at this time. Resolution ========== All Apache Tomcat 6.0.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-servers/tomcat-6.0.35" All Apache Tomcat 7.0.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-servers/tomcat-7.0.23" References ========== [ 1 ] CVE-2008-5515 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5515 [ 2 ] CVE-2009-0033 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0033 [ 3 ] CVE-2009-0580 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0580 [ 4 ] CVE-2009-0781 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0781 [ 5 ] CVE-2009-0783 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0783 [ 6 ] CVE-2009-2693 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2693 [ 7 ] CVE-2009-2901 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2901 [ 8 ] CVE-2009-2902 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2902 [ 9 ] CVE-2010-1157 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1157 [ 10 ] CVE-2010-2227 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2227 [ 11 ] CVE-2010-3718 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3718 [ 12 ] CVE-2010-4172 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4172 [ 13 ] CVE-2010-4312 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4312 [ 14 ] CVE-2011-0013 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0013 [ 15 ] CVE-2011-0534 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0534 [ 16 ] CVE-2011-1088 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1088 [ 17 ] CVE-2011-1183 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1183 [ 18 ] CVE-2011-1184 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1184 [ 19 ] CVE-2011-1419 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1419 [ 20 ] CVE-2011-1475 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1475 [ 21 ] CVE-2011-1582 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1582 [ 22 ] CVE-2011-2204 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2204 [ 23 ] CVE-2011-2481 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2481 [ 24 ] CVE-2011-2526 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2526 [ 25 ] CVE-2011-2729 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2729 [ 26 ] CVE-2011-3190 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3190 [ 27 ] CVE-2011-3375 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3375 [ 28 ] CVE-2011-4858 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4858 [ 29 ] CVE-2011-5062 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5062 [ 30 ] CVE-2011-5063 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5063 [ 31 ] CVE-2011-5064 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5064 [ 32 ] CVE-2012-0022 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0022 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201206-24.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2012 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . Release Date: 2012-02-06 Last Updated: 2012-02-06 ------------------------------------------------------------------------------ Potential Security Impact: Remote Denial of Service (DoS), access restriction bypass Source: Hewlett-Packard Company, HP Software Security Response Team VULNERABILITY SUMMARY Potential security vulnerabilities have been identified with HP-UX Apache Running Tomcat Servlet Engine. These vulnerabilities could be exploited remotely to create a Denial of Service (DoS) or to perform an access restriction bypass. References: CVE-2006-7243, CVE-2011-4858, CVE-2011-4885, CVE-2012-0022 SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. HP-UX B.11.23, B.11.31 running HP-UX Apache Web Server Suite v3.21 or earlier BACKGROUND CVSS 2.0 Base Metrics =========================================================== Reference Base Vector Base Score CVE-2006-7243 (AV:N/AC:L/Au:N/C:N/I:P/A:N) 5.0 CVE-2011-4858 (AV:N/AC:L/Au:N/C:N/I:N/A:P) 5.0 CVE-2011-4885 (AV:N/AC:L/Au:N/C:N/I:N/A:P) 5.0 CVE-2012-0022 (AV:N/AC:L/Au:N/C:N/I:N/A:P) 5.0 =========================================================== Information on CVSS is documented in HP Customer Notice: HPSN-2008-002 RESOLUTION HP has provided the following software updates to resolve the vulnerability. The updates are available for download from ftp://srt10728:Secure12@ftp.usa.hp.com Note: HP-UX Web Server Suite v3.22 contains HP-UX Tomcat-based Servlet Engine v5.5.35.01 Web Server Suite Version Apache Depot Name HP-UX Web Server Suite v.3.22 HP-UX B.11.23 HPUXWS22ATW-B322-64.depot HP-UX B.11.23 HPUXWS22ATW-B322-32.depot HP-UX B.11.31 HPUXWS22ATW-B322-64.depot HP-UX B.11.31 HPUXWS22ATW-B322-32.depot MANUAL ACTIONS: Yes - Update Install HP-UX Web Server Suite v3.22 or subsequent. PRODUCT SPECIFIC INFORMATION HP-UX Software Assistant: HP-UX Software Assistant is an enhanced application that replaces HP-UX Security Patch Check. It analyzes all Security Bulletins issued by HP and lists recommended actions that may apply to a specific HP-UX system. It can also download patches and create a depot automatically. For more information see https://www.hp.com/go/swa The following text is for use by the HP-UX Software Assistant. AFFECTED VERSIONS HP-UX Web Server Suite HP-UX B.11.23 HP-UX B.11.31 ================== hpuxws22TOMCAT.TOMCAT action: install revision B.5.5.35.01 or subsequent hpuxws22APCH32.APACHE hpuxws22APCH32.APACHE2 hpuxws22APCH32.AUTH_LDAP hpuxws22APCH32.AUTH_LDAP2 hpuxws22APCH32.MOD_JK hpuxws22APCH32.MOD_JK2 hpuxws22APCH32.MOD_PERL hpuxws22APCH32.MOD_PERL2 hpuxws22APCH32.PHP hpuxws22APCH32.PHP2 hpuxws22APCH32.WEBPROXY action: install revision B.2.2.15.11 or subsequent END AFFECTED VERSION HISTORY Version:1 (rev.1) - 06 February 2012 Initial release Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com. Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via Email: http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins Security Bulletin List: A list of HP Security Bulletins, updated periodically, is contained in HP Security Notice HPSN-2011-001: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c02964430 Security Bulletin Archive: A list of recently released Security Bulletins is available here: http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secBullArchive/ Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB. 3C = 3COM 3P = 3rd Party Software GN = HP General Software HF = HP Hardware and Firmware MP = MPE/iX MU = Multi-Platform Software NS = NonStop Servers OV = OpenVMS PI = Printing and Imaging PV = ProCurve ST = Storage Software TU = Tru64 UNIX UX = HP-UX Copyright 2012 Hewlett-Packard Development Company, L.P. Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental,special or consequential damages including downtime cost; lost profits;damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: tomcat6 security and bug fix update Advisory ID: RHSA-2012:0682-01 Product: JBoss Enterprise Web Server Advisory URL: https://rhn.redhat.com/errata/RHSA-2012-0682.html Issue date: 2012-05-21 CVE Names: CVE-2011-1184 CVE-2011-2204 CVE-2011-2526 CVE-2011-3190 CVE-2011-3375 CVE-2011-4858 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 CVE-2012-0022 ===================================================================== 1. Summary: Updated tomcat6 packages that fix multiple security issues and three bugs are now available for JBoss Enterprise Web Server 1.0.2 for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: JBoss Enterprise Web Server 1.0 for RHEL 5 Server - noarch JBoss Enterprise Web Server 1.0 for RHEL 6 Server - noarch 3. Description: Apache Tomcat is a servlet container. JBoss Enterprise Web Server includes the Tomcat Native library, providing Apache Portable Runtime (APR) support for Tomcat. References in this text to APR refer to the Tomcat Native implementation, not any other apr package. This update fixes the JBPAPP-4873, JBPAPP-6133, and JBPAPP-6852 bugs. It also resolves the following security issues: Multiple flaws weakened the Tomcat HTTP DIGEST authentication implementation, subjecting it to some of the weaknesses of HTTP BASIC authentication, for example, allowing remote attackers to perform session replay attacks. (CVE-2011-1184, CVE-2011-5062, CVE-2011-5063, CVE-2011-5064) A flaw was found in the way the Coyote (org.apache.coyote.ajp.AjpProcessor) and APR (org.apache.coyote.ajp.AjpAprProcessor) Tomcat AJP (Apache JServ Protocol) connectors processed certain POST requests. An attacker could send a specially-crafted request that would cause the connector to treat the message body as a new request. This allows arbitrary AJP messages to be injected, possibly allowing an attacker to bypass a web application's authentication checks and gain access to information they would otherwise be unable to access. The JK (org.apache.jk.server.JkCoyoteHandler) connector is used by default when the APR libraries are not present. The JK connector is not affected by this flaw. (CVE-2011-3190) A flaw in the way Tomcat recycled objects that contain data from user requests (such as IP addresses and HTTP headers) when certain errors occurred. If a user sent a request that caused an error to be logged, Tomcat would return a reply to the next request (which could be sent by a different user) with data from the first user's request, leading to information disclosure. Under certain conditions, a remote attacker could leverage this flaw to hijack sessions. (CVE-2011-3375) The Java hashCode() method implementation was susceptible to predictable hash collisions. This update introduces a limit on the number of parameters processed per request to mitigate this issue. The default limit is 512 for parameters and 128 for headers. These defaults can be changed by setting the org.apache.tomcat.util.http.Parameters.MAX_COUNT and org.apache.tomcat.util.http.MimeHeaders.MAX_COUNT system properties. (CVE-2011-4858) Tomcat did not handle large numbers of parameters and large parameter values efficiently. A remote attacker could make Tomcat use an excessive amount of CPU time by sending an HTTP request containing a large number of parameters or large parameter values. This update introduces limits on the number of parameters and headers processed per request to address this issue. Refer to the CVE-2011-4858 description for information about the org.apache.tomcat.util.http.Parameters.MAX_COUNT and org.apache.tomcat.util.http.MimeHeaders.MAX_COUNT system properties. (CVE-2012-0022) A flaw in the Tomcat MemoryUserDatabase. If a runtime exception occurred when creating a new user with a JMX client, that user's password was logged to Tomcat log files. Note: By default, only administrators have access to such log files. (CVE-2011-2204) A flaw in the way Tomcat handled sendfile request attributes when using the HTTP APR or NIO (Non-Blocking I/O) connector. A malicious web application running on a Tomcat instance could use this flaw to bypass security manager restrictions and gain access to files it would otherwise be unable to access, or possibly terminate the Java Virtual Machine (JVM). The HTTP NIO connector is used by default in JBoss Enterprise Web Server. (CVE-2011-2526) Red Hat would like to thank oCERT for reporting CVE-2011-4858, and the Apache Tomcat project for reporting CVE-2011-2526. oCERT acknowledges Julian Wälde and Alexander Klink as the original reporters of CVE-2011-4858. 4. Solution: Users of Tomcat should upgrade to these updated packages, which resolve these issues. Tomcat must be restarted for this update to take effect. Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 717013 - CVE-2011-2204 tomcat: password disclosure vulnerability 720948 - CVE-2011-2526 tomcat: security manager restrictions bypass 734868 - CVE-2011-3190 tomcat: authentication bypass and information disclosure 741401 - CVE-2011-1184 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 tomcat: Multiple weaknesses in HTTP DIGEST authentication 750521 - CVE-2011-4858 tomcat: hash table collisions CPU usage DoS (oCERT-2011-003) 782624 - CVE-2011-3375 tomcat: information disclosure due to improper response and request object recycling 783359 - CVE-2012-0022 tomcat: large number of parameters DoS 6. Package List: JBoss Enterprise Web Server 1.0 for RHEL 5 Server: Source: tomcat6-6.0.32-24_patch_07.ep5.el5.src.rpm noarch: tomcat6-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-admin-webapps-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-docs-webapp-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-el-1.0-api-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-javadoc-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-jsp-2.1-api-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-lib-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-log4j-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-servlet-2.5-api-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-webapps-6.0.32-24_patch_07.ep5.el5.noarch.rpm JBoss Enterprise Web Server 1.0 for RHEL 6 Server: Source: tomcat6-6.0.32-24_patch_07.ep5.el6.src.rpm noarch: tomcat6-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-admin-webapps-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-docs-webapp-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-el-1.0-api-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-javadoc-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-jsp-2.1-api-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-lib-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-log4j-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-servlet-2.5-api-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-webapps-6.0.32-24_patch_07.ep5.el6.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://www.redhat.com/security/data/cve/CVE-2011-1184.html https://www.redhat.com/security/data/cve/CVE-2011-2204.html https://www.redhat.com/security/data/cve/CVE-2011-2526.html https://www.redhat.com/security/data/cve/CVE-2011-3190.html https://www.redhat.com/security/data/cve/CVE-2011-3375.html https://www.redhat.com/security/data/cve/CVE-2011-4858.html https://www.redhat.com/security/data/cve/CVE-2011-5062.html https://www.redhat.com/security/data/cve/CVE-2011-5063.html https://www.redhat.com/security/data/cve/CVE-2011-5064.html https://www.redhat.com/security/data/cve/CVE-2012-0022.html https://access.redhat.com/security/updates/classification/#moderate http://tomcat.apache.org/security-6.html https://issues.jboss.org/browse/JBPAPP-4873 https://issues.jboss.org/browse/JBPAPP-6133 https://issues.jboss.org/browse/JBPAPP-6852 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2012 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFPunmrXlSAg2UNWIIRAkA4AKCTaGA0dlkzcdXw8BMDz6i6Kk31iQCbBwk5 HGbJnvqJAVX57f9/Kpj3+R4= =pyZw -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce . A flaw was found in the way JBoss Web handled UTF-8 surrogate pair characters. If JBoss Web was hosting an application with UTF-8 character encoding enabled, or that included user-supplied UTF-8 strings in a response, a remote attacker could use this flaw to cause a denial of service (infinite loop) on the JBoss Web server. Warning: Before applying this update, back up your JBoss Enterprise Application Platform's "jboss-as/server/[PROFILE]/deploy/" directory, along with all other customized configuration files. It comprises a set of offerings for enterprise customers who are looking for pre-configured profiles of JBoss Enterprise Middleware components that have been tested and certified together to provide an integrated experience. Refer to the JBoss Enterprise Portal Platform 4.3 CP07 Release Notes, available shortly from docs.redhat.com, for information on the most significant bug fixes included in this release. The following security fixes are also included: JBoss Seam 2 did not properly block access to JBoss Expression Language (EL) constructs in page exception handling, allowing arbitrary Java methods to be executed. A remote attacker could use this flaw to execute arbitrary code via a specially-crafted URL provided to certain applications based on the JBoss Seam 2 framework. Note: A properly configured and enabled Java Security Manager would prevent exploitation of this flaw. (CVE-2011-1484) Note: If you have created custom applications that are packaged with a copy of the JBoss Seam 2 library, those applications must be rebuilt with the updated jboss-seam.jar file provided by this update. (CVE-2011-1184, CVE-2011-5062, CVE-2011-5063, CVE-2011-5064) The invoker servlets, deployed by default via httpha-invoker, only performed access control on the HTTP GET and POST methods, allowing remote attackers to make unauthenticated requests by using different HTTP methods. Due to the second layer of authentication provided by a security interceptor, this issue is not exploitable on default installations unless an administrator has misconfigured the security interceptor or disabled it. Solution: The References section of this erratum contains a download link (you must log in to download the update). Note that if you have created custom applications that are packaged with a copy of the JBoss Seam 2 library, those applications must be rebuilt with the updated jboss-seam.jar file provided by this update. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. 5 client): Source: ftp://ftp.redhat.com/pub/redhat/linux/enterprise/5Client/en/os/SRPMS/tomcat5-5.5.23-0jpp.31.el5_8.src.rpm i386: tomcat5-debuginfo-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-jsp-2.0-api-5.5.23-0jpp.31.el5_8.i386.rpm tomcat5-servlet-2.4-api-5.5.23-0jpp.31.el5_8.i386.rpm x86_64: tomcat5-debuginfo-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-jsp-2.0-api-5.5.23-0jpp.31.el5_8.x86_64.rpm tomcat5-servlet-2.4-api-5.5.23-0jpp.31.el5_8.x86_64.rpm RHEL Desktop Workstation (v. Description: The JBoss Communications Platform (JBCP) is an open source VoIP platform certified for JAIN SLEE 1.1 and SIP Servlets 1.1 compliance. JBCP serves as a high performance core for Service Delivery Platforms (SDPs) and IP Multimedia Subsystems (IMSs) by leveraging J2EE to enable the convergence of data and video in Next-Generation Intelligent Network (NGIN) applications. ---------------------------------------------------------------------- Secunia is hiring! Find your next job here: http://secunia.com/company/jobs/ ---------------------------------------------------------------------- TITLE: Hitachi COBOL2002 Products Unspecified Vulnerability SECUNIA ADVISORY ID: SA47612 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/47612/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=47612 RELEASE DATE: 2012-01-20 DISCUSS ADVISORY: http://secunia.com/advisories/47612/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/47612/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=47612 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Hitachi has reported a vulnerability in some COBOL2002 products, which can be exploited by malicious users to compromise a vulnerable system. The vulnerability is caused due to an unspecified error. No further information is currently available. PROVIDED AND/OR DISCOVERED BY: Reported by the vendor. ORIGINAL ADVISORY: http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS12-002/index.html OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 3.06

sources: NVD: CVE-2011-4858 // CERT/CC: VU#903934 // CNVD: CNVD-2012-0341 // VULMON: CVE-2011-4858 // PACKETSTORM: 114139 // PACKETSTORM: 109542 // PACKETSTORM: 112906 // PACKETSTORM: 112904 // PACKETSTORM: 109272 // PACKETSTORM: 109367 // PACKETSTORM: 111782 // PACKETSTORM: 109274 // PACKETSTORM: 108859

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2012-0341

AFFECTED PRODUCTS

vendor:apachemodel:tomcatscope:eqversion:6.0.0

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.8

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.11

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.8

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:5.5.35

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.16

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.24

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.21

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.4

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.11

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.22

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.6

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.14

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.31

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.33

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.10

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.17

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.20

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.19

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.18

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.14

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.3

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.0

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.3

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.5

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.7

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.29

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.12

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.2

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.1

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.34

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.1

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.26

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.9

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.16

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.5

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.19

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.9

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.12

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.15

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.13

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.13

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.7

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.18

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.22

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.32

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.23

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.25

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.10

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.21

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.2

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.28

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.30

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.15

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.4

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.6

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.17

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.27

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.20

Trust: 1.0

vendor:apache tomcatmodel: - scope: - version: -

Trust: 0.8

vendor:microsoftmodel: - scope: - version: -

Trust: 0.8

vendor:oraclemodel: - scope: - version: -

Trust: 0.8

vendor:rubymodel: - scope: - version: -

Trust: 0.8

vendor:the php groupmodel: - scope: - version: -

Trust: 0.8

vendor:hitachimodel:cobol2002 net server suitescope:eqversion:2.x

Trust: 0.6

vendor:hitachimodel:cobol2002 net client suitescope:eqversion:2.x

Trust: 0.6

vendor:hitachimodel:cobol2002 net developerscope:eqversion:2.x

Trust: 0.6

sources: CERT/CC: VU#903934 // CNVD: CNVD-2012-0341 // NVD: CVE-2011-4858

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2011-4858
value: MEDIUM

Trust: 1.0

CARNEGIE MELLON: VU#903934
value: 10.80

Trust: 0.8

VULMON: CVE-2011-4858
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2011-4858
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

sources: CERT/CC: VU#903934 // VULMON: CVE-2011-4858 // NVD: CVE-2011-4858

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.0

sources: NVD: CVE-2011-4858

THREAT TYPE

remote

Trust: 0.3

sources: PACKETSTORM: 112906 // PACKETSTORM: 109272 // PACKETSTORM: 111782

TYPE

arbitrary

Trust: 0.1

sources: PACKETSTORM: 114139

EXPLOIT AVAILABILITY

sources: VULMON: CVE-2011-4858

PATCH

title:Patch for Hitachi COBOL2002 product has an unknown vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/8212

Trust: 0.6

title:Red Hat: Moderate: tomcat6 security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120475 - Security Advisory

Trust: 0.1

title:Red Hat: Moderate: tomcat5 security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120474 - Security Advisory

Trust: 0.1

title:Red Hat: Important: jbossweb security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120074 - Security Advisory

Trust: 0.1

title:Red Hat: Important: jbossweb security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120076 - Security Advisory

Trust: 0.1

title:Ubuntu Security Notice: tomcat6 vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-1359-1

Trust: 0.1

title:Red Hat: Moderate: tomcat5 security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120680 - Security Advisory

Trust: 0.1

title:Red Hat: Moderate: tomcat6 security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120682 - Security Advisory

Trust: 0.1

title: - url:https://github.com/Live-Hack-CVE/CVE-2011-4084

Trust: 0.1

sources: CNVD: CNVD-2012-0341 // VULMON: CVE-2011-4858

EXTERNAL IDS

db:OCERTid:OCERT-2011-003

Trust: 1.9

db:CERT/CCid:VU#903934

Trust: 1.9

db:NVDid:CVE-2011-4858

Trust: 1.9

db:SECUNIAid:48791

Trust: 1.1

db:SECUNIAid:48790

Trust: 1.1

db:SECUNIAid:48549

Trust: 1.1

db:SECUNIAid:54971

Trust: 1.1

db:SECUNIAid:55115

Trust: 1.1

db:BIDid:51200

Trust: 1.1

db:SECUNIAid:47612

Trust: 0.8

db:CNVDid:CNVD-2012-0341

Trust: 0.6

db:EXPLOIT-DBid:2012

Trust: 0.1

db:VULMONid:CVE-2011-4858

Trust: 0.1

db:PACKETSTORMid:114139

Trust: 0.1

db:PACKETSTORMid:109542

Trust: 0.1

db:PACKETSTORMid:112906

Trust: 0.1

db:PACKETSTORMid:112904

Trust: 0.1

db:PACKETSTORMid:109272

Trust: 0.1

db:PACKETSTORMid:109367

Trust: 0.1

db:PACKETSTORMid:111782

Trust: 0.1

db:PACKETSTORMid:109274

Trust: 0.1

db:HITACHIid:HS12-002

Trust: 0.1

db:PACKETSTORMid:108859

Trust: 0.1

sources: CERT/CC: VU#903934 // CNVD: CNVD-2012-0341 // VULMON: CVE-2011-4858 // PACKETSTORM: 114139 // PACKETSTORM: 109542 // PACKETSTORM: 112906 // PACKETSTORM: 112904 // PACKETSTORM: 109272 // PACKETSTORM: 109367 // PACKETSTORM: 111782 // PACKETSTORM: 109274 // PACKETSTORM: 108859 // NVD: CVE-2011-4858

REFERENCES

url:http://www.ocert.org/advisories/ocert-2011-003.html

Trust: 1.9

url:http://www.nruns.com/_downloads/advisory28122011.pdf

Trust: 1.9

url:http://rhn.redhat.com/errata/rhsa-2012-0074.html

Trust: 1.2

url:http://rhn.redhat.com/errata/rhsa-2012-0078.html

Trust: 1.2

url:https://bugzilla.redhat.com/show_bug.cgi?id=750521

Trust: 1.1

url:http://tomcat.apache.org/tomcat-7.0-doc/changelog.html

Trust: 1.1

url:http://www.kb.cert.org/vuls/id/903934

Trust: 1.1

url:https://github.com/firefart/hashcollision-dos-poc/blob/master/hashtablepoc.py

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=132871655717248&w=2

Trust: 1.1

url:http://www.debian.org/security/2012/dsa-2401

Trust: 1.1

url:http://secunia.com/advisories/48791

Trust: 1.1

url:http://secunia.com/advisories/48790

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=136485229118404&w=2

Trust: 1.1

url:http://secunia.com/advisories/54971

Trust: 1.1

url:http://secunia.com/advisories/55115

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0089.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0406.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0075.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0325.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0076.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0077.html

Trust: 1.1

url:http://www.securityfocus.com/bid/51200

Trust: 1.1

url:https://oval.cisecurity.org/repository/search/definition/oval%3aorg.mitre.oval%3adef%3a18886

Trust: 1.1

url:http://secunia.com/advisories/48549

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=133294394108746&w=2

Trust: 1.1

url:http://mail-archives.apache.org/mod_mbox/tomcat-announce/201112.mbox/%3c4efb9800.5010106%40apache.org%3e

Trust: 1.0

url:http://www.cs.rice.edu/~scrosby/hash/crosbywallach_usenixsec2003.pdf

Trust: 0.8

url:http://technet.microsoft.com/en-us/security/bulletin/ms11-100.mspx

Trust: 0.8

url:http://blogs.technet.com/b/srd/archive/2011/12/27/more-information-about-the-december-2011-asp-net-vulnerability.aspx

Trust: 0.8

url:http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-talk/391606

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2011-4858

Trust: 0.8

url:http://secunia.com/advisories/47612/

Trust: 0.7

url:https://nvd.nist.gov/vuln/detail/cve-2011-2526

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2011-1184

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2012-0022

Trust: 0.6

url:https://www.redhat.com/security/data/cve/cve-2011-4858.html

Trust: 0.6

url:https://access.redhat.com/security/team/contact/

Trust: 0.6

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.6

url:http://bugzilla.redhat.com/):

Trust: 0.6

url:https://www.redhat.com/security/data/cve/cve-2011-5063.html

Trust: 0.5

url:https://www.redhat.com/security/data/cve/cve-2012-0022.html

Trust: 0.5

url:https://www.redhat.com/security/data/cve/cve-2011-2526.html

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2011-5063

Trust: 0.5

url:https://www.redhat.com/security/data/cve/cve-2011-5064.html

Trust: 0.5

url:https://www.redhat.com/security/data/cve/cve-2011-1184.html

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2011-5064

Trust: 0.5

url:https://www.redhat.com/security/data/cve/cve-2011-5062.html

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2011-5062

Trust: 0.5

url:https://access.redhat.com/security/team/key/#package

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2011-2204

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2011-3190

Trust: 0.3

url:https://access.redhat.com/security/updates/classification/#moderate

Trust: 0.3

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2011-3375

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2011-2204.html

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2011-3190.html

Trust: 0.2

url:https://issues.jboss.org/browse/jbpapp-6133

Trust: 0.2

url:https://issues.jboss.org/browse/jbpapp-4873

Trust: 0.2

url:https://access.redhat.com/knowledge/articles/11258

Trust: 0.2

url:http://tomcat.apache.org/security-5.html

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2011-4610.html

Trust: 0.2

url:https://access.redhat.com/kb/docs/doc-11259

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2011-4610

Trust: 0.2

url:https://docs.redhat.com/docs/en-us/index.html

Trust: 0.2

url:https://cwe.mitre.org/data/definitions/399.html

Trust: 0.1

url:http://mail-archives.apache.org/mod_mbox/tomcat-announce/201112.mbox/%3c4efb9800.5010106@apache.org%3e

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2012:0475

Trust: 0.1

url:https://github.com/live-hack-cve/cve-2011-4084

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://usn.ubuntu.com/1359-1/

Trust: 0.1

url:https://www.exploit-db.com/exploits/2012/

Trust: 0.1

url:http://tools.cisco.com/security/center/viewalert.x?alertid=24901

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-0783

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0033

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-0033

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-0781

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2729

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-2902

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-5062

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-2902

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0534

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1183

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-3718

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1475

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0534

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0013

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-5063

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-3718

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1582

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0580

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-4172

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-5064

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-4312

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-2693

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1475

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0781

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-2227

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1088

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-0580

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-2901

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2526

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1183

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1184

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2204

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2008-5515

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-0022

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-2693

Trust: 0.1

url:http://security.gentoo.org/

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-1157

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4172

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1088

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2481

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0783

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4312

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-4858

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-2227

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2481

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0013

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-1157

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2729

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2008-5515

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-2901

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-3190

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1419

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-3375

Trust: 0.1

url:http://security.gentoo.org/glsa/glsa-201206-24.xml

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1582

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1419

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-4885

Trust: 0.1

url:http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secbullarchive/

Trust: 0.1

url:http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins

Trust: 0.1

url:https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docdisplay/?docid=emr_na-c02964430

Trust: 0.1

url:https://www.hp.com/go/swa

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2006-7243

Trust: 0.1

url:https://issues.jboss.org/browse/jbpapp-6852

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2011-3375.html

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0682.html

Trust: 0.1

url:http://tomcat.apache.org/security-6.html

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0680.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-4085

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1484

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?downloadtype=distributions&product=jbportal&version=4.3+cp07

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2011-1484.html

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0091.html

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2011-4085.html

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0474.html

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?product=communications.platform&downloadtype=distributions

Trust: 0.1

url:http://www.hitachi.co.jp/prod/comp/soft1/global/security/info/vuls/hs12-002/index.html

Trust: 0.1

url:http://secunia.com/company/jobs/

Trust: 0.1

url:http://secunia.com/vulnerability_intelligence/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/47612/#comments

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=47612

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

sources: CERT/CC: VU#903934 // CNVD: CNVD-2012-0341 // VULMON: CVE-2011-4858 // PACKETSTORM: 114139 // PACKETSTORM: 109542 // PACKETSTORM: 112906 // PACKETSTORM: 112904 // PACKETSTORM: 109272 // PACKETSTORM: 109367 // PACKETSTORM: 111782 // PACKETSTORM: 109274 // PACKETSTORM: 108859 // NVD: CVE-2011-4858

CREDITS

Red Hat

Trust: 0.6

sources: PACKETSTORM: 112906 // PACKETSTORM: 112904 // PACKETSTORM: 109272 // PACKETSTORM: 109367 // PACKETSTORM: 111782 // PACKETSTORM: 109274

SOURCES

db:CERT/CCid:VU#903934
db:CNVDid:CNVD-2012-0341
db:VULMONid:CVE-2011-4858
db:PACKETSTORMid:114139
db:PACKETSTORMid:109542
db:PACKETSTORMid:112906
db:PACKETSTORMid:112904
db:PACKETSTORMid:109272
db:PACKETSTORMid:109367
db:PACKETSTORMid:111782
db:PACKETSTORMid:109274
db:PACKETSTORMid:108859
db:NVDid:CVE-2011-4858

LAST UPDATE DATE

2025-10-20T02:06:51.755000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#903934date:2016-02-15T00:00:00
db:CNVDid:CNVD-2012-0341date:2012-02-01T00:00:00
db:VULMONid:CVE-2011-4858date:2018-01-09T00:00:00
db:NVDid:CVE-2011-4858date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CERT/CCid:VU#903934date:2011-12-28T00:00:00
db:CNVDid:CNVD-2012-0341date:2012-02-01T00:00:00
db:VULMONid:CVE-2011-4858date:2012-01-05T00:00:00
db:PACKETSTORMid:114139date:2012-06-24T23:54:31
db:PACKETSTORMid:109542date:2012-02-08T16:07:24
db:PACKETSTORMid:112906date:2012-05-22T00:21:41
db:PACKETSTORMid:112904date:2012-05-22T00:20:13
db:PACKETSTORMid:109272date:2012-02-01T02:55:02
db:PACKETSTORMid:109367date:2012-02-03T00:18:35
db:PACKETSTORMid:111782date:2012-04-12T03:11:30
db:PACKETSTORMid:109274date:2012-02-01T02:55:27
db:PACKETSTORMid:108859date:2012-01-20T08:20:00
db:NVDid:CVE-2011-4858date:2012-01-05T19:55:01.033