Upstream information
Description
Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.NVD CVSS v2 Base Score: 5.8 (AV:N/AC:M/Au:N/C:N/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entry: 575083 SUSE Security Advisories:- SUSE-SR:2010:008, published Wed, 07 Apr 2010 13:00:00 +0000
- openSUSE-SU-2012:1700-1, published Thu, 27 Dec 2012 17:08:34 +0100 (CET)
- openSUSE-SU-2012:1701-1, published Thu, 27 Dec 2012 17:09:46 +0100 (CET)
- openSUSE-SU-2013:0147-1, published Wed, 23 Jan 2013 14:05:42 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| Open Enterprise Server |
| sles9-nlpos.x86 core9.ppc core9.ia64 core9.x86 core9.x86-64 sles9-oes.x86 core9.s390x core9.s390 YOU Patch Nr: 12585 |
| SUSE Linux Enterprise SDK 10 SP2 SUSE Linux Enterprise Server for SAP 10 SP2 |
| sles10-sp2.x86 sle10-sp2-sdk.x86-64 sle10-sp2-sdk.x86 sle10-sp2-sdk.ppc sles10-sp2.s390x sles10-sp2.ia64 sles10-sp2.ppc sle10-sp2-sdk.s390x sles10-sp2.x86-64 sle10-sp2-sdk.ia64 ZYPP Patch Nr: 7003 |
| openSUSE 11.0 |
| |
| openSUSE 11.1 |
| |
| openSUSE 11.2 |
| |
| SUSE Linux Enterprise SDK 10 SP3 SUSE Linux Enterprise Server 10 SP3 SUSE Linux Enterprise Server for SAP 10 SP3 |
| sle10-sp3-sdk.s390x sles10-sp3.x86-64 sles10-sp3.x86 sles10-sp3.s390x sles10-sp3.ia64 sles10-sp3.ppc sle10-sp3-sdk.ia64 sle10-sp3-sdk.ppc sle10-sp3-sdk.x86-64 sle10-sp3-sdk.x86 ZYPP Patch Nr: 6839 |
| SUSE Linux Enterprise SDK 11 GA |
| sle11-sdk.x86-64 sle11-sdk.x86 sle11-sdk.ppc sle11-sdk.ia64 sle11-sdk.s390x SAT Patch Nr: 1957 |
| SUSE Linux Enterprise SDK 10 SP2 SUSE Linux Enterprise Server for SAP 10 SP2 |
| sle10-sp2-sdk.ia64 sles10-sp2.s390x sles10-sp2.ia64 sles10-sp2.x86-64 sles10-sp2.x86-64 sles10-sp2.ppc sle10-sp2-sdk.x86-64 sle10-sp2-sdk.x86-64 sles10-sp2.x86 sles10-sp2.s390x sle10-sp2-sdk.x86 sle10-sp2-sdk.ppc sle10-sp2-sdk.x86 sle10-sp2-sdk.s390x sles10-sp2.ppc sles10-sp2.ia64 sle10-sp2-sdk.s390x sles10-sp2.x86 sle10-sp2-sdk.ia64 sle10-sp2-sdk.ppc ZYPP Patch Nr: 6841 |
