---
title: "CVE-2014-0119\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-0119?format=md
keywords: index, follow
---

# CVE-2014-0119

Publication date 31 May 2014

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does
not properly constrain the class loader that accesses the XML parser used
with an XSLT stylesheet, which allows remote attackers to (1) read
arbitrary files via a crafted web application that provides an XML external
entity declaration in conjunction with an entity reference, related to an
XML External Entity (XXE) issue, or (2) read files associated with
different web applications on a single Tomcat instance via a crafted web
application.

### From the Ubuntu Security Team

It was discovered that the Tomcat XML parser incorrectly handled XML
External Entities (XXE). A remote attacker could possibly use this issue to
read arbitrary files. This issue only affected Ubuntu 14.04 LTS.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2014-0119?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| tomcat6 | 21.04 hirsute | Not in release |
| 20.10 groovy | Not in release |
| 20.04 LTS focal | Not in release |
| 19.10 eoan | Not in release |
| 19.04 disco | Not in release |
| 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 17.04 zesty | Not in release |
| 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.10 utopic | Not affected |
| 14.04 LTS trusty | Fixed 6.0.39-1ubuntu0.1 |
| 13.10 saucy | Ignored end of life |
| 12.04 LTS precise | Ignored end of life |
| 10.04 LTS lucid | Ignored end of life |
| tomcat7 | 21.04 hirsute | Not in release |
| 20.10 groovy | Not in release |
| 20.04 LTS focal | Not in release |
| 19.10 eoan | Not in release |
| 19.04 disco | Not in release |
| 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 17.04 zesty | Not affected |
| 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.10 utopic | Not affected |
| 14.04 LTS trusty | Fixed 7.0.52-1ubuntu0.3 |
| 13.10 saucy | Ignored end of life |
| 12.04 LTS precise | Ignored end of life |
| 10.04 LTS lucid | Not in release |
| tomcat8 | 21.04 hirsute | Not in release |
| 20.10 groovy | Not in release |
| 20.04 LTS focal | Not in release |
| 19.10 eoan | Not in release |
| 19.04 disco | Not in release |
| 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 17.04 zesty | Not affected |
| 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.10 utopic | Not affected |
| 14.04 LTS trusty | Not in release |
| 13.10 saucy | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2014-0119?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

patch is intrusive

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| tomcat6 | * Upstream:   <http://svn.apache.org/viewvc?view=revision&revision=1589640> * Upstream:   <http://svn.apache.org/viewvc?view=revision&revision=1593815> * Upstream:   <http://svn.apache.org/viewvc?view=revision&revision=1593821> |
| tomcat7 | * Upstream:   <http://svn.apache.org/viewvc?view=revision&revision=1589763> * Upstream:   <http://svn.apache.org/viewvc?view=revision&revision=1589851> * Upstream:   <http://svn.apache.org/viewvc?view=revision&revision=1588199> * Upstream:   <http://svn.apache.org/viewvc?view=revision&revision=1589997> * Upstream:   <http://svn.apache.org/viewvc?view=revision&revision=1590028> * Upstream:   <http://svn.apache.org/viewvc?view=revision&revision=1590036> * Vendor:   <https://git.centos.org/blob/rpms!tomcat.git/f90819793e4da6c0cc3e7c19d29b48710e29d05b/SOURCES!tomcat-7.0.42-CVE-2014-0119.patch> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0119)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-0119)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-0119)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-0119)

### Related Ubuntu Security Notices (USN)

+ [USN-2654-1](https://usn.ubuntu.com/USN-2654-1)
+ Tomcat vulnerabilities
+ 25 June 2015

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2014-0119>
