{"id":"SUSE-SU-2015:1565-1","summary":"Security update for tomcat6","details":"This update for Tomcat fixes the following security issues:\n\n- CVE-2014-7810: Security manager bypass via EL expressions. (bsc#931442)\nIt was found that the expression language resolver evaluated expressions within a\nprivileged code section. A malicious web application could have used this flaw to\nbypass security manager protections.\n\n- CVE-2014-0227: Limited DoS in chunked transfer encoding input filter. (bsc#917127)\nIt was discovered that the ChunkedInputFilter implementation did not fail subsequent\nattempts to read input early enough. A remote attacker could have used this flaw to\nperform a denial of service attack, by streaming an unlimited quantity of data,\nleading to consumption of server resources.\n\n- CVE-2014-0230: Non-persistent DoS attack by feeding data by aborting an upload\nIt was possible for a remote attacker to trigger a non-persistent DoS attack by\nfeeding data by aborting an upload. (bsc#926762)\n\nAdditionally, the following non-security issues have been fixed:\n\n- Fix rights of all files within /usr/share/tomcat6/bin. (bsc#906152)\n- Don't overwrite /var/run/tomcat6.pid when Tomcat is already running. (bsc#934219)\n- Miscellaneous fixes and improvements to Tomcat's init script. (bsc#932698)\n","modified":"2026-02-04T03:45:06.548347Z","published":"2015-09-11T01:45:16Z","related":["CVE-2014-0227","CVE-2014-0230","CVE-2014-7810"],"upstream":["CVE-2014-0227","CVE-2014-0230","CVE-2014-7810"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20151565-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/906152"},{"type":"REPORT","url":"https://bugzilla.suse.com/917127"},{"type":"REPORT","url":"https://bugzilla.suse.com/926762"},{"type":"REPORT","url":"https://bugzilla.suse.com/931442"},{"type":"REPORT","url":"https://bugzilla.suse.com/932698"},{"type":"REPORT","url":"https://bugzilla.suse.com/934219"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-0227"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-0230"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-7810"}],"affected":[{"package":{"name":"tomcat6","ecosystem":"SUSE:Linux Enterprise Server 11 SP4","purl":"pkg:rpm/suse/tomcat6&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.41-0.47.1"}]}],"ecosystem_specific":{"binaries":[{"tomcat6-javadoc":"6.0.41-0.47.1","tomcat6-jsp-2_1-api":"6.0.41-0.47.1","tomcat6-lib":"6.0.41-0.47.1","tomcat6-servlet-2_5-api":"6.0.41-0.47.1","tomcat6-webapps":"6.0.41-0.47.1","tomcat6":"6.0.41-0.47.1","tomcat6-admin-webapps":"6.0.41-0.47.1","tomcat6-docs-webapp":"6.0.41-0.47.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:1565-1.json"}},{"package":{"name":"tomcat6","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","purl":"pkg:rpm/suse/tomcat6&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.41-0.47.1"}]}],"ecosystem_specific":{"binaries":[{"tomcat6-jsp-2_1-api":"6.0.41-0.47.1","tomcat6-lib":"6.0.41-0.47.1","tomcat6-servlet-2_5-api":"6.0.41-0.47.1","tomcat6-webapps":"6.0.41-0.47.1","tomcat6":"6.0.41-0.47.1","tomcat6-admin-webapps":"6.0.41-0.47.1","tomcat6-docs-webapp":"6.0.41-0.47.1","tomcat6-javadoc":"6.0.41-0.47.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:1565-1.json"}}],"schema_version":"1.7.3"}