tomcat6-6.0.24-64.AXS4

エラータID: AXSA:2014-284:02

Release date: 
Tuesday, April 29, 2014 - 18:29
Subject: 
tomcat6-6.0.24-64.AXS4
Affected Channels: 
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity: 
High
Description: 

Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process.

Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world.

Security issues fixed with this release:

• CVE-2013-4286
Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incorrect identification of a request's length and conduct request-smuggling attacks via (1) multiple Content-Length headers or (2) a Content-Length header and a "Transfer-Encoding: chunked" header. NOTE: this vulnerability exists because of an incomplete fix for CVE-2005-2090.

• CVE-2013-4322
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field, which allows remote attackers to cause a denial of service by streaming data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3544.

• CVE-2014-0050
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. tomcat6-6.0.24-64.AXS4.src.rpm
    MD5: f9154272f1c050e691c04f20a25ea731
    SHA-256: 443c5de8a8bb03dddbb02dfcfae286971069046c08501f6586721236f6a3b2b9
    Size: 3.44 MB

Asianux Server 4 for x86
  1. tomcat6-6.0.24-64.AXS4.noarch.rpm
    MD5: dc5c0460ad89bee9e7335f5e428242bb
    SHA-256: 12ae7e0f13596e1032bdf5e256fdfb90299e82fc20dbef77e124c87ec04cf6dc
    Size: 89.35 kB
  2. tomcat6-el-2.1-api-6.0.24-64.AXS4.noarch.rpm
    MD5: 4e763e9b636a198cdb3eaab32f51369b
    SHA-256: d135e093066a5e9d948dcc1c2cd2c28120cfb3e4cc6e57a59fa2b5fa886a06c4
    Size: 45.26 kB
  3. tomcat6-jsp-2.1-api-6.0.24-64.AXS4.noarch.rpm
    MD5: a8f6a2ced2aac7ab0971e014929a413c
    SHA-256: b5df8a82119a3a1cebea85919c6934baa659c109e3f285461d0cc8eef7a5034e
    Size: 82.14 kB
  4. tomcat6-lib-6.0.24-64.AXS4.noarch.rpm
    MD5: c385f19b2ee17e07a3ca87571825fdaf
    SHA-256: 0bc0318f092158846b9d5b4e7f9b524d48301c7fa4345f42461770fe350d8fe6
    Size: 2.88 MB
  5. tomcat6-servlet-2.5-api-6.0.24-64.AXS4.noarch.rpm
    MD5: 19b9f26502bce8b539edc982abb8bddd
    SHA-256: 1ea655441e92c73f1cadb6d1340cd372db6fb01265ab554d4fa20304941e2cf0
    Size: 96.04 kB

Asianux Server 4 for x86_64
  1. tomcat6-6.0.24-64.AXS4.noarch.rpm
    MD5: e89c20b64f84f1e954cfccf04b21576a
    SHA-256: 22d5da2a652bf33d787c9a62ebbde313fcb30934a49e9dbc785c0c0f746f040d
    Size: 88.91 kB
  2. tomcat6-el-2.1-api-6.0.24-64.AXS4.noarch.rpm
    MD5: 6477efcead7c74f329905aec7a61fdce
    SHA-256: b5870f62c97cd897cfff7f3b8a13d04527bebf471c005c03c1c6369ce0f1973d
    Size: 44.81 kB
  3. tomcat6-jsp-2.1-api-6.0.24-64.AXS4.noarch.rpm
    MD5: 7976cae0de19c70db75537ecccfa2586
    SHA-256: fd5ab298bc0c6b1bc9fa13d64f29751b10567fde4e82096042b4af8ceb5016c5
    Size: 81.70 kB
  4. tomcat6-lib-6.0.24-64.AXS4.noarch.rpm
    MD5: 6f4ececd5bc838510bbc3bac3ecf8229
    SHA-256: 774787beab7fd433f141111c136b99d8b0695b5ba7534f76e1ff06b6a63e46de
    Size: 2.88 MB
  5. tomcat6-servlet-2.5-api-6.0.24-64.AXS4.noarch.rpm
    MD5: 0f42098cf577941ed2d4d9cb9b472a22
    SHA-256: f8299f0f3697c019b4e0080cb1a50cdd652d46d59f8c21e2149e57f2d87258ba
    Size: 95.59 kB