CVE-2009-2693
Publication date 28 January 2010
Last updated 24 July 2024
Ubuntu priority
Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.
Status
Package | Ubuntu Release | Status |
---|---|---|
tomcat5 | ||
tomcat5.5 | ||
tomcat6 | ||
Patch details
Package | Patch details |
---|---|
tomcat5.5 | |
tomcat6 |
References
Related Ubuntu Security Notices (USN)
- USN-899-1
- Tomcat vulnerabilities
- 11 February 2010