SUSE-SU-2015:1337-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1337-1
SUSE-SU-2015:1337-1
Summary: Security update for tomcat6
Details: This update of tomcat6 fixes: * apache-tomcat-CVE-2012-3544.patch (bnc#831119) * use chown --no-dereference to prevent symlink attacks on log (bnc#822177#c7/prevents CVE-2013-1976) * Fix tomcat init scripts generating malformed classpath ( http://youtrack.jetbrains.com/issue/JT-18545 <http://youtrack.jetbrains.com/issue/JT-18545> ) bnc#804992 (patch from m407) * fix a typo in initscript (bnc#768772 ) * copy all shell scripts (bnc#818948) Security Issue references: * CVE-2012-3544 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3544> * CVE-2013-1976 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1976> * CVE-2012-0022 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0022>
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151337-1/, https://bugzilla.suse.com/768772, https://bugzilla.suse.com/804992, https://bugzilla.suse.com/818948, https://bugzilla.suse.com/822177, https://bugzilla.suse.com/831119, https://bugzilla.suse.com/906152, https://bugzilla.suse.com/917127, https://bugzilla.suse.com/918195, https://bugzilla.suse.com/926762, https://bugzilla.suse.com/931442, https://bugzilla.suse.com/932698, https://www.suse.com/security/cve/CVE-2012-0022, https://www.suse.com/security/cve/CVE-2012-3544, https://www.suse.com/security/cve/CVE-2013-1976, https://www.suse.com/security/cve/CVE-2014-0227, https://www.suse.com/security/cve/CVE-2014-0230, https://www.suse.com/security/cve/CVE-2014-7810
