{"affected":[{"ecosystem_specific":{"binaries":[{"tomcat":"7.0.78-7.13.4","tomcat-admin-webapps":"7.0.78-7.13.4","tomcat-docs-webapp":"7.0.78-7.13.4","tomcat-el-2_2-api":"7.0.78-7.13.4","tomcat-javadoc":"7.0.78-7.13.4","tomcat-jsp-2_2-api":"7.0.78-7.13.4","tomcat-lib":"7.0.78-7.13.4","tomcat-servlet-3_0-api":"7.0.78-7.13.4","tomcat-webapps":"7.0.78-7.13.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"tomcat","purl":"pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"7.0.78-7.13.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"tomcat":"7.0.78-7.13.4","tomcat-admin-webapps":"7.0.78-7.13.4","tomcat-docs-webapp":"7.0.78-7.13.4","tomcat-el-2_2-api":"7.0.78-7.13.4","tomcat-javadoc":"7.0.78-7.13.4","tomcat-jsp-2_2-api":"7.0.78-7.13.4","tomcat-lib":"7.0.78-7.13.4","tomcat-servlet-3_0-api":"7.0.78-7.13.4","tomcat-webapps":"7.0.78-7.13.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","name":"tomcat","purl":"pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"7.0.78-7.13.4"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\nTomcat was updated to version 7.0.78, fixing various bugs and security issues.\n\nFor full details see https://tomcat.apache.org/tomcat-7.0-doc/changelog.html\n\nSecurity issues fixed:\n\n- CVE-2016-0762: A realm timing attack in tomcat was fixed which could disclose existence of users (bsc#1007854)\n- CVE-2016-3092: Usage of vulnerable FileUpload package could have resulted in denial of service (bsc#986359) \n- CVE-2016-5018: A security manager bypass via a Tomcat utility method that was accessible to web applications was fixed. (bsc#1007855)\n- CVE-2016-5388: Setting HTTP_PROXY environment variable via Proxy header (bsc#988489)\n- CVE-2016-6794: A tomcat system property disclosure was fixed. (bsc#1007857)\n- CVE-2016-6796: A tomcat security manager bypass via manipulation of the configuration parameters for the JSP Servlet. (bsc#1007858)\n- CVE-2016-6797: A tomcat unrestricted access to global resources via ResourceLinkFactory was fixed. (bsc#1007853)\n- CVE-2016-6816: A HTTP Request smuggling vulnerability due to permitting invalid character in HTTP requests was fixed. (bsc#1011812)\n- CVE-2016-8735: A Remote code execution vulnerability in JmxRemoteLifecycleListener was fixed (bsc#1011805)\n- CVE-2016-8745: A Tomcat Information Disclosure in the error handling of send file code for the NIO HTTP connector was fixed. (bsc#1015119)\n- CVE-2017-5647: A tomcat information disclosure in pipelined request processing was fixed. (bsc#1033448)\n- CVE-2017-5648: A tomcat information disclosure due to using incorrect facade objects was fixed (bsc#1033447)\n","id":"SUSE-SU-2017:1660-1","modified":"2017-06-23T09:07:07Z","published":"2017-06-23T09:07:07Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20171660-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1007853"},{"type":"REPORT","url":"https://bugzilla.suse.com/1007854"},{"type":"REPORT","url":"https://bugzilla.suse.com/1007855"},{"type":"REPORT","url":"https://bugzilla.suse.com/1007857"},{"type":"REPORT","url":"https://bugzilla.suse.com/1007858"},{"type":"REPORT","url":"https://bugzilla.suse.com/1011805"},{"type":"REPORT","url":"https://bugzilla.suse.com/1011812"},{"type":"REPORT","url":"https://bugzilla.suse.com/1015119"},{"type":"REPORT","url":"https://bugzilla.suse.com/1033447"},{"type":"REPORT","url":"https://bugzilla.suse.com/1033448"},{"type":"REPORT","url":"https://bugzilla.suse.com/986359"},{"type":"REPORT","url":"https://bugzilla.suse.com/988489"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-0762"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-3092"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5018"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5388"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6794"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6796"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6797"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6816"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-8735"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-8745"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5647"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5648"}],"related":["CVE-2016-0762","CVE-2016-3092","CVE-2016-5018","CVE-2016-5388","CVE-2016-6794","CVE-2016-6796","CVE-2016-6797","CVE-2016-6816","CVE-2016-8735","CVE-2016-8745","CVE-2017-5647","CVE-2017-5648"],"summary":"Security update for tomcat","upstream":["CVE-2016-0762","CVE-2016-3092","CVE-2016-5018","CVE-2016-5388","CVE-2016-6794","CVE-2016-6796","CVE-2016-6797","CVE-2016-6816","CVE-2016-8735","CVE-2016-8745","CVE-2017-5647","CVE-2017-5648"]}