SUSE-SU-2015:1565-1

    Dashboard / Vulnerabilities / SUSE-SU-2015:1565-1

    SUSE-SU-2015:1565-1

    Published: 11 Sept 2015Last Modified: 4 Feb 2026

    Summary: Security update for tomcat6

    Details: This update for Tomcat fixes the following security issues: - CVE-2014-7810: Security manager bypass via EL expressions. (bsc#931442) It was found that the expression language resolver evaluated expressions within a privileged code section. A malicious web application could have used this flaw to bypass security manager protections. - CVE-2014-0227: Limited DoS in chunked transfer encoding input filter. (bsc#917127) It was discovered that the ChunkedInputFilter implementation did not fail subsequent attempts to read input early enough. A remote attacker could have used this flaw to perform a denial of service attack, by streaming an unlimited quantity of data, leading to consumption of server resources. - CVE-2014-0230: Non-persistent DoS attack by feeding data by aborting an upload It was possible for a remote attacker to trigger a non-persistent DoS attack by feeding data by aborting an upload. (bsc#926762) Additionally, the following non-security issues have been fixed: - Fix rights of all files within /usr/share/tomcat6/bin. (bsc#906152) - Don't overwrite /var/run/tomcat6.pid when Tomcat is already running. (bsc#934219) - Miscellaneous fixes and improvements to Tomcat's init script. (bsc#932698)

    Affected packages

    Package

    Name: tomcat6

    Purl: pkg:rpm/suse/tomcat6&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -6.0.41-0.47.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High