---
title: "CVE-2013-1976\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2013-1976?format=md
keywords: index, follow
---

# CVE-2013-1976

Publication date 9 July 2013

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the
RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0,
and Red Hat Enterprise Linux 5 and 6, allow local users to change the
ownership of arbitrary files via a symlink attack on (a) tomcat5-initd.log,
(b) tomcat6-initd.log, (c) catalina.out, or (d) tomcat7-initd.log.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2013-1976?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| tomcat6 | 13.04 raring | Not affected |
| 12.10 quantal | Not affected |
| 12.04 LTS precise | Not affected |
| 10.04 LTS lucid | Not affected |
| tomcat7 | 13.04 raring | Not affected |
| 12.10 quantal | Not affected |
| 12.04 LTS precise | Not affected |
| 10.04 LTS lucid | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

in redhat-specific init script

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1976)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-1976)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2013-1976)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2013-1976)

### Other references

* <https://rhn.redhat.com/errata/RHSA-2013-0869.html>
* <https://www.cve.org/CVERecord?id=CVE-2013-1976>
