Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.703669
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 3669-1 (tomcat7 - security update)
Zusammenfassung:Dawid Golunski of LegalHackers discovered;that the Tomcat init script performed unsafe file handling, which could result in;local privilege escalation.
Beschreibung:Summary:
Dawid Golunski of LegalHackers discovered
that the Tomcat init script performed unsafe file handling, which could result in
local privilege escalation.

Affected Software/OS:
tomcat7 on Debian Linux

Solution:
For the stable distribution (jessie), this
problem has been fixed in version 7.0.56-3+deb8u4.

We recommend that you upgrade your tomcat7 packages.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-1240
BugTraq ID: 93263
http://www.securityfocus.com/bid/93263
Bugtraq: 20161001 CVE-2016-1240 - Tomcat packaging on Debian-based distros - Local Root Privilege Escalation (Google Search)
http://www.securityfocus.com/archive/1/539519/100/0/threaded
Debian Security Information: DSA-3669 (Google Search)
http://www.debian.org/security/2016/dsa-3669
Debian Security Information: DSA-3670 (Google Search)
http://www.debian.org/security/2016/dsa-3670
https://www.exploit-db.com/exploits/40450/
https://security.gentoo.org/glsa/201705-09
http://legalhackers.com/advisories/Tomcat-DebPkgs-Root-Privilege-Escalation-Exploit-CVE-2016-1240.html
RedHat Security Advisories: RHSA-2017:0455
https://access.redhat.com/errata/RHSA-2017:0455
RedHat Security Advisories: RHSA-2017:0456
https://access.redhat.com/errata/RHSA-2017:0456
RedHat Security Advisories: RHSA-2017:0457
http://rhn.redhat.com/errata/RHSA-2017-0457.html
http://www.securitytracker.com/id/1036845
http://www.ubuntu.com/usn/USN-3081-1
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.