{"affected":[{"ecosystem_specific":{"binaries":[{"tomcat6":"6.0.41-0.47.1","tomcat6-admin-webapps":"6.0.41-0.47.1","tomcat6-docs-webapp":"6.0.41-0.47.1","tomcat6-javadoc":"6.0.41-0.47.1","tomcat6-jsp-2_1-api":"6.0.41-0.47.1","tomcat6-lib":"6.0.41-0.47.1","tomcat6-servlet-2_5-api":"6.0.41-0.47.1","tomcat6-webapps":"6.0.41-0.47.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP4","name":"tomcat6","purl":"pkg:rpm/suse/tomcat6&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.0.41-0.47.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"tomcat6":"6.0.41-0.47.1","tomcat6-admin-webapps":"6.0.41-0.47.1","tomcat6-docs-webapp":"6.0.41-0.47.1","tomcat6-javadoc":"6.0.41-0.47.1","tomcat6-jsp-2_1-api":"6.0.41-0.47.1","tomcat6-lib":"6.0.41-0.47.1","tomcat6-servlet-2_5-api":"6.0.41-0.47.1","tomcat6-webapps":"6.0.41-0.47.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","name":"tomcat6","purl":"pkg:rpm/suse/tomcat6&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"6.0.41-0.47.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for Tomcat fixes the following security issues:\n\n- CVE-2014-7810: Security manager bypass via EL expressions. (bsc#931442)\nIt was found that the expression language resolver evaluated expressions within a\nprivileged code section. A malicious web application could have used this flaw to\nbypass security manager protections.\n\n- CVE-2014-0227: Limited DoS in chunked transfer encoding input filter. (bsc#917127)\nIt was discovered that the ChunkedInputFilter implementation did not fail subsequent\nattempts to read input early enough. A remote attacker could have used this flaw to\nperform a denial of service attack, by streaming an unlimited quantity of data,\nleading to consumption of server resources.\n\n- CVE-2014-0230: Non-persistent DoS attack by feeding data by aborting an upload\nIt was possible for a remote attacker to trigger a non-persistent DoS attack by\nfeeding data by aborting an upload. (bsc#926762)\n\nAdditionally, the following non-security issues have been fixed:\n\n- Fix rights of all files within /usr/share/tomcat6/bin. (bsc#906152)\n- Don't overwrite /var/run/tomcat6.pid when Tomcat is already running. (bsc#934219)\n- Miscellaneous fixes and improvements to Tomcat's init script. (bsc#932698)\n","id":"SUSE-SU-2015:1565-1","modified":"2015-09-11T01:45:16Z","published":"2015-09-11T01:45:16Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20151565-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/906152"},{"type":"REPORT","url":"https://bugzilla.suse.com/917127"},{"type":"REPORT","url":"https://bugzilla.suse.com/926762"},{"type":"REPORT","url":"https://bugzilla.suse.com/931442"},{"type":"REPORT","url":"https://bugzilla.suse.com/932698"},{"type":"REPORT","url":"https://bugzilla.suse.com/934219"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-0227"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-0230"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-7810"}],"related":["CVE-2014-0227","CVE-2014-0230","CVE-2014-7810"],"summary":"Security update for tomcat6","upstream":["CVE-2014-0227","CVE-2014-0230","CVE-2014-7810"]}