CVE 2016-1240
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-java packages before 7.0.52-1ubuntu0.7 on Ubuntu 14.04 LTS, and tomcat8 and libtomcat8-java packages before 8.0.32-1ubuntu1.2 on Ubuntu 16.04 LTS allows local users with access to the tomcat account to gain root privileges via a symlink attack on the Catalina log file, as demonstrated by /var/log/
Related bugs and status
CVE-2016-1240 (Candidate) is related to these bugs:
Bug #1609819: CVE-2015-5345 patch issue on tomcat7
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1609819 | CVE-2015-5345 patch issue on tomcat7 | tomcat7 (Ubuntu) | Medium | Fix Released | ||
1609819 | CVE-2015-5345 patch issue on tomcat7 | tomcat7 (Ubuntu Trusty) | Medium | Fix Released |
Bug #1799990: tomcat7 doesn't start after upgrade to 7.0.68-1ubuntu0.3
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1799990 | tomcat7 doesn't start after upgrade to 7.0.68-1ubuntu0.3 | tomcat7 (Ubuntu) | Undecided | Fix Released | ||
1799990 | tomcat7 doesn't start after upgrade to 7.0.68-1ubuntu0.3 | tomcat7 (Ubuntu Xenial) | Undecided | Fix Released | ||
1799990 | tomcat7 doesn't start after upgrade to 7.0.68-1ubuntu0.3 | tomcat7 (Ubuntu Trusty) | Undecided | Invalid |
Bug #1817567: backport tomcat & dependencies for OpenJDK 11
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1817567 | backport tomcat & dependencies for OpenJDK 11 | tomcat9 (Ubuntu) | Undecided | New | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | websocket-api (Ubuntu) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | eclipse-emf (Ubuntu Bionic) | Undecided | Fix Committed | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | jetty9 (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | swt4-gtk (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | tomcat-native (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | tomcat8 (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | eclipse-debian-helper (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | eclipse-jdt-core (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | eclipse-jdt-debug (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | eclipse-jdt-ui (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | eclipse-platform-debug (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | eclipse-platform-resources (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | eclipse-platform-runtime (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | eclipse-platform-team (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | eclipse-platform-text (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | eclipse-platform-ua (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | eclipse-platform-ui (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | el-api (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | equinox-bundles (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | equinox-framework (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | equinox-p2 (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | jsp-api (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | servlet-api (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | tomcat9 (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | websocket-api (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | libeclipse-emf (Ubuntu Bionic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | jetty9 (Ubuntu Cosmic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | tomcat8 (Ubuntu Cosmic) | Undecided | Fix Released | ||
1817567 | backport tomcat & dependencies for OpenJDK 11 | tomcat9 (Ubuntu Cosmic) | Undecided | Fix Released |
See the
CVE page on Mitre.org
for more details.