Ubuntu Security Notice USN-2654-1

Discussion in 'News Aggregator' started by Packet Storm, 25 Jun 2015.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 2654-1 - It was discovered that the Tomcat XML parser incorrectly handled XML External Entities (XXE). A remote attacker could possibly use this issue to read arbitrary files. This issue only affected Ubuntu 14.04 LTS. It was discovered that Tomcat incorrectly handled data with malformed chunked transfer coding. A remote attacker could possibly use this issue to conduct HTTP request smuggling attacks, or cause Tomcat to consume resources, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...