ELSA-2016-2045

ELSA-2016-2045 - tomcat6 security and bug fix update

Type:SECURITY
Impact:IMPORTANT
Release Date:2016-10-10

Description


[0:6.0.24-98]
- Resolves: rhbz#1362210 CVE-2016-5388 Tomcat: CGI sets environmental variable based on user supplied Proxy request header
- Resolves: rhbz#1368119

[0:6.0.24-97]
- Resolves: rhbz#1367051 CVE-2015-5174 URL Normalization issue
- Resolves: rhbz#1367054 CVE-2016-0706 Security Manager bypass via StatusManagerServlet
- Resolves: rhbz#1367058 CVE-2016-0714 Security Manager bypass via persistence mechanisms
- Resolves: rhbz#1367054 CVE-2015-5345 Directory disclosure

[0:6.0.24-96]
- Resolves: rhbz#1357123 rpm -V tomcat6 fails due on /var/log/tomcat6/catalina.out


Related CVEs


CVE-2016-0706
CVE-2016-6325
CVE-2015-5345
CVE-2016-0714
CVE-2016-5388
CVE-2015-5174

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 6 (i386) tomcat6-6.0.24-98.el6_8.src.rpm8c07c6a62e09f5bbf223aa2ffbe533f3270b21c0c841d2d6940b463d4e597900ELSA-2020-2529ol6_i386_latest
tomcat6-6.0.24-98.el6_8.src.rpm8c07c6a62e09f5bbf223aa2ffbe533f3270b21c0c841d2d6940b463d4e597900ELSA-2020-2529ol6_i386_latest_archive
tomcat6-6.0.24-98.el6_8.src.rpm8c07c6a62e09f5bbf223aa2ffbe533f3270b21c0c841d2d6940b463d4e597900ELSA-2020-2529ol6_u8_i386_patch
tomcat6-6.0.24-98.el6_8.src.rpm8c07c6a62e09f5bbf223aa2ffbe533f3270b21c0c841d2d6940b463d4e597900ELSA-2020-2529ol6_u9_i386_base
tomcat6-6.0.24-98.el6_8.noarch.rpm1a2b256ae4df90267a3b68c178bc6d7270745a7ff2a9347c3009e26bd5db86ccELSA-2020-2529ol6_i386_latest
tomcat6-6.0.24-98.el6_8.noarch.rpm1a2b256ae4df90267a3b68c178bc6d7270745a7ff2a9347c3009e26bd5db86ccELSA-2020-2529ol6_i386_latest_archive
tomcat6-6.0.24-98.el6_8.noarch.rpm1a2b256ae4df90267a3b68c178bc6d7270745a7ff2a9347c3009e26bd5db86ccELSA-2020-2529ol6_u8_i386_patch
tomcat6-6.0.24-98.el6_8.noarch.rpm1a2b256ae4df90267a3b68c178bc6d7270745a7ff2a9347c3009e26bd5db86ccELSA-2020-2529ol6_u9_i386_base
tomcat6-admin-webapps-6.0.24-98.el6_8.noarch.rpmf0fdf851a6deaab67aebb9fcde2fc076d374281fcc6d0baba72368f5e8cf38b0ELSA-2020-2529ol6_i386_latest
tomcat6-admin-webapps-6.0.24-98.el6_8.noarch.rpmf0fdf851a6deaab67aebb9fcde2fc076d374281fcc6d0baba72368f5e8cf38b0ELSA-2020-2529ol6_i386_latest_archive
tomcat6-admin-webapps-6.0.24-98.el6_8.noarch.rpmf0fdf851a6deaab67aebb9fcde2fc076d374281fcc6d0baba72368f5e8cf38b0ELSA-2020-2529ol6_u8_i386_patch
tomcat6-admin-webapps-6.0.24-98.el6_8.noarch.rpmf0fdf851a6deaab67aebb9fcde2fc076d374281fcc6d0baba72368f5e8cf38b0ELSA-2020-2529ol6_u9_i386_base
tomcat6-docs-webapp-6.0.24-98.el6_8.noarch.rpmcfec9745b0317b7ec29139f809d5d1bae57eef38cb1c72df0a5159e588c23bfeELSA-2020-2529ol6_i386_latest
tomcat6-docs-webapp-6.0.24-98.el6_8.noarch.rpmcfec9745b0317b7ec29139f809d5d1bae57eef38cb1c72df0a5159e588c23bfeELSA-2020-2529ol6_i386_latest_archive
tomcat6-docs-webapp-6.0.24-98.el6_8.noarch.rpmcfec9745b0317b7ec29139f809d5d1bae57eef38cb1c72df0a5159e588c23bfeELSA-2020-2529ol6_u8_i386_patch
tomcat6-docs-webapp-6.0.24-98.el6_8.noarch.rpmcfec9745b0317b7ec29139f809d5d1bae57eef38cb1c72df0a5159e588c23bfeELSA-2020-2529ol6_u9_i386_base
tomcat6-el-2.1-api-6.0.24-98.el6_8.noarch.rpm030571030bb627d2b879d2c0e727bc23cfbd2b42d9d5d30fce21be41875c56c6ELSA-2020-2529ol6_i386_latest
tomcat6-el-2.1-api-6.0.24-98.el6_8.noarch.rpm030571030bb627d2b879d2c0e727bc23cfbd2b42d9d5d30fce21be41875c56c6ELSA-2020-2529ol6_i386_latest_archive
tomcat6-el-2.1-api-6.0.24-98.el6_8.noarch.rpm030571030bb627d2b879d2c0e727bc23cfbd2b42d9d5d30fce21be41875c56c6ELSA-2020-2529ol6_u8_i386_patch
tomcat6-el-2.1-api-6.0.24-98.el6_8.noarch.rpm030571030bb627d2b879d2c0e727bc23cfbd2b42d9d5d30fce21be41875c56c6ELSA-2020-2529ol6_u9_i386_base
tomcat6-javadoc-6.0.24-98.el6_8.noarch.rpm8f71ea59fe1c9d54912c60ab96a9764595c14692125205978f94f6c3e211aaa0ELSA-2020-2529ol6_i386_latest
tomcat6-javadoc-6.0.24-98.el6_8.noarch.rpm8f71ea59fe1c9d54912c60ab96a9764595c14692125205978f94f6c3e211aaa0ELSA-2020-2529ol6_i386_latest_archive
tomcat6-javadoc-6.0.24-98.el6_8.noarch.rpm8f71ea59fe1c9d54912c60ab96a9764595c14692125205978f94f6c3e211aaa0ELSA-2020-2529ol6_u8_i386_patch
tomcat6-javadoc-6.0.24-98.el6_8.noarch.rpm8f71ea59fe1c9d54912c60ab96a9764595c14692125205978f94f6c3e211aaa0ELSA-2020-2529ol6_u9_i386_base
tomcat6-jsp-2.1-api-6.0.24-98.el6_8.noarch.rpm401d5ba443144105a270305aeef627713ea49725ab1471106957be5e1ca79e5dELSA-2020-2529ol6_i386_latest
tomcat6-jsp-2.1-api-6.0.24-98.el6_8.noarch.rpm401d5ba443144105a270305aeef627713ea49725ab1471106957be5e1ca79e5dELSA-2020-2529ol6_i386_latest_archive
tomcat6-jsp-2.1-api-6.0.24-98.el6_8.noarch.rpm401d5ba443144105a270305aeef627713ea49725ab1471106957be5e1ca79e5dELSA-2020-2529ol6_u8_i386_patch
tomcat6-jsp-2.1-api-6.0.24-98.el6_8.noarch.rpm401d5ba443144105a270305aeef627713ea49725ab1471106957be5e1ca79e5dELSA-2020-2529ol6_u9_i386_base
tomcat6-lib-6.0.24-98.el6_8.noarch.rpm72f7e89013dee9ea017cf48ddbb27bf6cfb11489ef3180b3ceee38b6887f3735ELSA-2020-2529ol6_i386_latest
tomcat6-lib-6.0.24-98.el6_8.noarch.rpm72f7e89013dee9ea017cf48ddbb27bf6cfb11489ef3180b3ceee38b6887f3735ELSA-2020-2529ol6_i386_latest_archive
tomcat6-lib-6.0.24-98.el6_8.noarch.rpm72f7e89013dee9ea017cf48ddbb27bf6cfb11489ef3180b3ceee38b6887f3735ELSA-2020-2529ol6_u8_i386_patch
tomcat6-lib-6.0.24-98.el6_8.noarch.rpm72f7e89013dee9ea017cf48ddbb27bf6cfb11489ef3180b3ceee38b6887f3735ELSA-2020-2529ol6_u9_i386_base
tomcat6-servlet-2.5-api-6.0.24-98.el6_8.noarch.rpm9bea7b9f949d379f1cf7e483120f2477f39faa4d41ab3c7be71e334bd85f192eELSA-2020-2529ol6_i386_latest
tomcat6-servlet-2.5-api-6.0.24-98.el6_8.noarch.rpm9bea7b9f949d379f1cf7e483120f2477f39faa4d41ab3c7be71e334bd85f192eELSA-2020-2529ol6_i386_latest_archive
tomcat6-servlet-2.5-api-6.0.24-98.el6_8.noarch.rpm9bea7b9f949d379f1cf7e483120f2477f39faa4d41ab3c7be71e334bd85f192eELSA-2020-2529ol6_u8_i386_patch
tomcat6-servlet-2.5-api-6.0.24-98.el6_8.noarch.rpm9bea7b9f949d379f1cf7e483120f2477f39faa4d41ab3c7be71e334bd85f192eELSA-2020-2529ol6_u9_i386_base
tomcat6-webapps-6.0.24-98.el6_8.noarch.rpm1516e9b2c7f182c4086fd754130d03ae93e960cf69f2360619a96592a03337adELSA-2020-2529ol6_i386_latest
tomcat6-webapps-6.0.24-98.el6_8.noarch.rpm1516e9b2c7f182c4086fd754130d03ae93e960cf69f2360619a96592a03337adELSA-2020-2529ol6_i386_latest_archive
tomcat6-webapps-6.0.24-98.el6_8.noarch.rpm1516e9b2c7f182c4086fd754130d03ae93e960cf69f2360619a96592a03337adELSA-2020-2529ol6_u8_i386_patch
tomcat6-webapps-6.0.24-98.el6_8.noarch.rpm1516e9b2c7f182c4086fd754130d03ae93e960cf69f2360619a96592a03337adELSA-2020-2529ol6_u9_i386_base
Oracle Linux 6 (x86_64) tomcat6-6.0.24-98.el6_8.src.rpm8c07c6a62e09f5bbf223aa2ffbe533f3270b21c0c841d2d6940b463d4e597900ELSA-2020-2529ol6_u8_x86_64_patch
tomcat6-6.0.24-98.el6_8.src.rpm8c07c6a62e09f5bbf223aa2ffbe533f3270b21c0c841d2d6940b463d4e597900ELSA-2020-2529ol6_u9_x86_64_base
tomcat6-6.0.24-98.el6_8.src.rpm8c07c6a62e09f5bbf223aa2ffbe533f3270b21c0c841d2d6940b463d4e597900ELSA-2020-2529ol6_x86_64_latest
tomcat6-6.0.24-98.el6_8.src.rpm8c07c6a62e09f5bbf223aa2ffbe533f3270b21c0c841d2d6940b463d4e597900ELSA-2020-2529ol6_x86_64_latest_archive
tomcat6-6.0.24-98.el6_8.noarch.rpm1a2b256ae4df90267a3b68c178bc6d7270745a7ff2a9347c3009e26bd5db86ccELSA-2020-2529ol6_u8_x86_64_patch
tomcat6-6.0.24-98.el6_8.noarch.rpm1a2b256ae4df90267a3b68c178bc6d7270745a7ff2a9347c3009e26bd5db86ccELSA-2020-2529ol6_u9_x86_64_base
tomcat6-6.0.24-98.el6_8.noarch.rpm1a2b256ae4df90267a3b68c178bc6d7270745a7ff2a9347c3009e26bd5db86ccELSA-2020-2529ol6_x86_64_latest
tomcat6-6.0.24-98.el6_8.noarch.rpm1a2b256ae4df90267a3b68c178bc6d7270745a7ff2a9347c3009e26bd5db86ccELSA-2020-2529ol6_x86_64_latest_archive
tomcat6-admin-webapps-6.0.24-98.el6_8.noarch.rpmf0fdf851a6deaab67aebb9fcde2fc076d374281fcc6d0baba72368f5e8cf38b0ELSA-2020-2529ol6_u8_x86_64_patch
tomcat6-admin-webapps-6.0.24-98.el6_8.noarch.rpmf0fdf851a6deaab67aebb9fcde2fc076d374281fcc6d0baba72368f5e8cf38b0ELSA-2020-2529ol6_u9_x86_64_base
tomcat6-admin-webapps-6.0.24-98.el6_8.noarch.rpmf0fdf851a6deaab67aebb9fcde2fc076d374281fcc6d0baba72368f5e8cf38b0ELSA-2020-2529ol6_x86_64_latest
tomcat6-admin-webapps-6.0.24-98.el6_8.noarch.rpmf0fdf851a6deaab67aebb9fcde2fc076d374281fcc6d0baba72368f5e8cf38b0ELSA-2020-2529ol6_x86_64_latest_archive
tomcat6-docs-webapp-6.0.24-98.el6_8.noarch.rpmcfec9745b0317b7ec29139f809d5d1bae57eef38cb1c72df0a5159e588c23bfeELSA-2020-2529ol6_u8_x86_64_patch
tomcat6-docs-webapp-6.0.24-98.el6_8.noarch.rpmcfec9745b0317b7ec29139f809d5d1bae57eef38cb1c72df0a5159e588c23bfeELSA-2020-2529ol6_u9_x86_64_base
tomcat6-docs-webapp-6.0.24-98.el6_8.noarch.rpmcfec9745b0317b7ec29139f809d5d1bae57eef38cb1c72df0a5159e588c23bfeELSA-2020-2529ol6_x86_64_latest
tomcat6-docs-webapp-6.0.24-98.el6_8.noarch.rpmcfec9745b0317b7ec29139f809d5d1bae57eef38cb1c72df0a5159e588c23bfeELSA-2020-2529ol6_x86_64_latest_archive
tomcat6-el-2.1-api-6.0.24-98.el6_8.noarch.rpm030571030bb627d2b879d2c0e727bc23cfbd2b42d9d5d30fce21be41875c56c6ELSA-2020-2529ol6_u8_x86_64_patch
tomcat6-el-2.1-api-6.0.24-98.el6_8.noarch.rpm030571030bb627d2b879d2c0e727bc23cfbd2b42d9d5d30fce21be41875c56c6ELSA-2020-2529ol6_u9_x86_64_base
tomcat6-el-2.1-api-6.0.24-98.el6_8.noarch.rpm030571030bb627d2b879d2c0e727bc23cfbd2b42d9d5d30fce21be41875c56c6ELSA-2020-2529ol6_x86_64_latest
tomcat6-el-2.1-api-6.0.24-98.el6_8.noarch.rpm030571030bb627d2b879d2c0e727bc23cfbd2b42d9d5d30fce21be41875c56c6ELSA-2020-2529ol6_x86_64_latest_archive
tomcat6-javadoc-6.0.24-98.el6_8.noarch.rpm8f71ea59fe1c9d54912c60ab96a9764595c14692125205978f94f6c3e211aaa0ELSA-2020-2529ol6_u8_x86_64_patch
tomcat6-javadoc-6.0.24-98.el6_8.noarch.rpm8f71ea59fe1c9d54912c60ab96a9764595c14692125205978f94f6c3e211aaa0ELSA-2020-2529ol6_u9_x86_64_base
tomcat6-javadoc-6.0.24-98.el6_8.noarch.rpm8f71ea59fe1c9d54912c60ab96a9764595c14692125205978f94f6c3e211aaa0ELSA-2020-2529ol6_x86_64_latest
tomcat6-javadoc-6.0.24-98.el6_8.noarch.rpm8f71ea59fe1c9d54912c60ab96a9764595c14692125205978f94f6c3e211aaa0ELSA-2020-2529ol6_x86_64_latest_archive
tomcat6-jsp-2.1-api-6.0.24-98.el6_8.noarch.rpm401d5ba443144105a270305aeef627713ea49725ab1471106957be5e1ca79e5dELSA-2020-2529ol6_u8_x86_64_patch
tomcat6-jsp-2.1-api-6.0.24-98.el6_8.noarch.rpm401d5ba443144105a270305aeef627713ea49725ab1471106957be5e1ca79e5dELSA-2020-2529ol6_u9_x86_64_base
tomcat6-jsp-2.1-api-6.0.24-98.el6_8.noarch.rpm401d5ba443144105a270305aeef627713ea49725ab1471106957be5e1ca79e5dELSA-2020-2529ol6_x86_64_latest
tomcat6-jsp-2.1-api-6.0.24-98.el6_8.noarch.rpm401d5ba443144105a270305aeef627713ea49725ab1471106957be5e1ca79e5dELSA-2020-2529ol6_x86_64_latest_archive
tomcat6-lib-6.0.24-98.el6_8.noarch.rpm72f7e89013dee9ea017cf48ddbb27bf6cfb11489ef3180b3ceee38b6887f3735ELSA-2020-2529ol6_u8_x86_64_patch
tomcat6-lib-6.0.24-98.el6_8.noarch.rpm72f7e89013dee9ea017cf48ddbb27bf6cfb11489ef3180b3ceee38b6887f3735ELSA-2020-2529ol6_u9_x86_64_base
tomcat6-lib-6.0.24-98.el6_8.noarch.rpm72f7e89013dee9ea017cf48ddbb27bf6cfb11489ef3180b3ceee38b6887f3735ELSA-2020-2529ol6_x86_64_latest
tomcat6-lib-6.0.24-98.el6_8.noarch.rpm72f7e89013dee9ea017cf48ddbb27bf6cfb11489ef3180b3ceee38b6887f3735ELSA-2020-2529ol6_x86_64_latest_archive
tomcat6-servlet-2.5-api-6.0.24-98.el6_8.noarch.rpm9bea7b9f949d379f1cf7e483120f2477f39faa4d41ab3c7be71e334bd85f192eELSA-2020-2529ol6_u8_x86_64_patch
tomcat6-servlet-2.5-api-6.0.24-98.el6_8.noarch.rpm9bea7b9f949d379f1cf7e483120f2477f39faa4d41ab3c7be71e334bd85f192eELSA-2020-2529ol6_u9_x86_64_base
tomcat6-servlet-2.5-api-6.0.24-98.el6_8.noarch.rpm9bea7b9f949d379f1cf7e483120f2477f39faa4d41ab3c7be71e334bd85f192eELSA-2020-2529ol6_x86_64_latest
tomcat6-servlet-2.5-api-6.0.24-98.el6_8.noarch.rpm9bea7b9f949d379f1cf7e483120f2477f39faa4d41ab3c7be71e334bd85f192eELSA-2020-2529ol6_x86_64_latest_archive
tomcat6-webapps-6.0.24-98.el6_8.noarch.rpm1516e9b2c7f182c4086fd754130d03ae93e960cf69f2360619a96592a03337adELSA-2020-2529ol6_u8_x86_64_patch
tomcat6-webapps-6.0.24-98.el6_8.noarch.rpm1516e9b2c7f182c4086fd754130d03ae93e960cf69f2360619a96592a03337adELSA-2020-2529ol6_u9_x86_64_base
tomcat6-webapps-6.0.24-98.el6_8.noarch.rpm1516e9b2c7f182c4086fd754130d03ae93e960cf69f2360619a96592a03337adELSA-2020-2529ol6_x86_64_latest
tomcat6-webapps-6.0.24-98.el6_8.noarch.rpm1516e9b2c7f182c4086fd754130d03ae93e960cf69f2360619a96592a03337adELSA-2020-2529ol6_x86_64_latest_archive



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete