Release date:
Updated on:
Affected Systems:
Apache Group Tomcat 7.x
Apache Group Tomcat 6.x
Apache Group Tomcat 5.x
Unaffected system:
Apache Group Tomcat 7.0.12
Apache Group Tomcat 6.0.33
Apache Group Tomcat 5.5.34
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49762
Cve id: CVE-2011-1184
Tomcat is a Servlet container developed by the Jakarta project under the Apache Software Foundation. According to the technical specifications provided by Sun Microsystems, Tomcat supports Servlet and JavaServer Page (JSP, it also provides some special functions as Web servers.
Tomcat implements multiple security vulnerabilities during HTTP digest authentication. Remote attackers can exploit these vulnerabilities to bypass security restrictions and perform illegal attacks.
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://jakarta.apache.org/tomcat/index.html