UBUNTU-CVE-2016-0762
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-0762
UBUNTU-CVE-2016-0762
Summary:
Details: The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default configuration includes the LockOutRealm which makes exploitation of this vulnerability harder.
References: https://ubuntu.com/security/CVE-2016-0762, http://markmail.org/message/pzuk6hauzljnm4r7?q=list:org.apache.tomcat.announce/, https://ubuntu.com/security/notices/USN-3177-1, https://ubuntu.com/security/notices/USN-4557-1, https://www.cve.org/CVERecord?id=CVE-2016-0762
Affected packages
Package
Name: tomcat6
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
