Summary
Ubuntu Update for Linux kernel vulnerabilities USN-899-1
Solution
Please Install the Updated Packages.
Insight
It was discovered that Tomcat did not correctly validate WAR filenames or paths when deploying. A remote attacker could send a specially crafted WAR file to be deployed and cause arbitrary files and directories to be created, overwritten, or deleted.
Affected
tomcat6 vulnerabilities on Ubuntu 8.10 ,
Ubuntu 9.04 ,
Ubuntu 9.10
Severity
Classification
-
CVE CVE-2009-2693, CVE-2009-2901, CVE-2009-2902 -
CVSS Base Score: 5.8
AV:N/AC:M/Au:N/C:N/I:P/A:P
Related Vulnerabilities