MGASA-2017-0400
Dashboard / Vulnerabilities / MGASA-2017-0400
Summary: Updated tomcat packages fix security vulnerability
Details: When running with HTTP PUTs enabled (e.g. via setting the readonly initialization parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server (CVE-2017-12617).
References: https://advisories.mageia.org/MGASA-2017-0400.html, https://bugs.mageia.org/show_bug.cgi?id=21933, https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.82, https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.47
Affected packages
Package
Name: tomcat
Purl: pkg:rpm/mageia/tomcat?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
