CVE-2013-2071
Publication date 10 May 2013
Last updated 24 July 2024
Ubuntu priority
java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.
Status
Package | Ubuntu Release | Status |
---|---|---|
tomcat6 | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
tomcat7 | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
Patch details
Package | Patch details |
---|---|
tomcat7 |
References
Related Ubuntu Security Notices (USN)
- USN-1841-1
- Tomcat vulnerabilities
- 28 May 2013