CVE-2011-3375
Published: 18 January 2012
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
Notes
Author | Note |
---|---|
mdeslaur | advisory says Tomcat 6.0.30 to 6.0.33 |
Priority
Status
Package | Release | Status |
---|---|---|
tomcat5.5 Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
upstream |
Needs triage
|
|
tomcat6 Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Not vulnerable
(6.0.24-2ubuntu1.9)
|
|
maverick |
Not vulnerable
(6.0.28-2ubuntu1.5)
|
|
natty |
Not vulnerable
(6.0.28-10ubuntu2.2)
|
|
oneiric |
Released
(6.0.32-5ubuntu1.2)
|
|
precise |
Not vulnerable
(6.0.35-1)
|
|
quantal |
Not vulnerable
(6.0.35-1)
|
|
upstream |
Released
(6.0.35)
|
|
Patches: upstream: http://svn.apache.org/viewvc?view=revision&revision=1185998 |
||
tomcat7 Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Released
(7.0.21-1ubuntu0.1)
|
|
precise |
Not vulnerable
(7.0.26-1ubuntu1)
|
|
quantal |
Not vulnerable
(7.0.29-0ubuntu1)
|
|
upstream |
Released
(7.0.22)
|
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3375
- http://tomcat.apache.org/security.html
- http://tomcat.apache.org/security-7.html
- http://tomcat.apache.org/security-6.html
- http://seclists.org/fulldisclosure/2012/Jan/236
- https://ubuntu.com/security/notices/USN-1359-1
- NVD
- Launchpad
- Debian