Ubuntu Security Notice USN-3665-1

Discussion in 'News Aggregator' started by Packet Storm, 1 Jun 2018.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3665-1 - It was discovered that Tomcat incorrectly handled being configured with HTTP PUTs enabled. A remote attacker could use this issue to upload a JSP file to the server and execute arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 17.10. It was discovered that Tomcat contained incorrect documentation regarding description of the search algorithm used by the CGI Servlet to identify which script to execute. This issue only affected Ubuntu 17.10. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...