|
|
|
|
| |
Credit:
The original article can be found at: http://www.securityfocus.com/bid/49143
The information has been provided by Wilfried Weissmann.
|
| |
Vulnerable Systems:
* Apache Software Foundation Tomcat 7.0.15
* Apache Software Foundation Tomcat 7.0.14
* Apache Software Foundation Tomcat 7.0.13
* Apache Software Foundation Tomcat 7.0.12
* Apache Software Foundation Tomcat 7.0.12
* Apache Software Foundation Tomcat 7.0.9
* Apache Software Foundation Tomcat 7.0.8
* Apache Software Foundation Tomcat 7.0.8
* Apache Software Foundation Tomcat 7.0.7
* Apache Software Foundation Tomcat 7.0.6
* Apache Software Foundation Tomcat 7.0.6
* Apache Software Foundation Tomcat 7.0.4
* Apache Software Foundation Tomcat 7.0.4
* Apache Software Foundation Tomcat 7.0.3
* Apache Software Foundation Tomcat 7.0.3
* Apache Software Foundation Tomcat 7.0.2
* Apache Software Foundation Tomcat 7.0.2
* Apache Software Foundation Tomcat 7.0.1
* Apache Software Foundation Tomcat 7.0.1
* Apache Software Foundation Tomcat 7.0 beta
* Apache Software Foundation Tomcat 7.0
* Apache Software Foundation Tomcat 5.5.32
* Apache Software Foundation Tomcat 7.0.5
* Apache Software Foundation Tomcat 7.0.19
* Apache Software Foundation Tomcat 7.0.18
* Apache Software Foundation Tomcat 7.0.17
* Apache Software Foundation Tomcat 7.0.11
* Apache Software Foundation Tomcat 7.0.10
* Apache Software Foundation Tomcat 7.0
* Apache Software Foundation Tomcat 6.0.32
* Apache Software Foundation Tomcat 6.0.31
* Apache Software Foundation Tomcat 6.0.30
* Apache Software Foundation Tomcat 5.5.33
* Apache Software Foundation Tomcat 5.5.33
* Apache Software Foundation Geronimo 2.1.7
* Apache Software Foundation Geronimo 2.1.6
* Apache Software Foundation Geronimo 2.1.5
* Apache Software Foundation Geronimo 2.1.4
* Apache Software Foundation Geronimo 2.1.3
* Apache Software Foundation Geronimo 2.1.2
* Apache Software Foundation Geronimo 2.1.1
* Apache Software Foundation Geronimo 2.0.2
* Apache Software Foundation Geronimo 2.0.1
* Apache Software Foundation Geronimo 1.1.1
* Apache Software Foundation Geronimo 1.1
* Apache Software Foundation Geronimo 1.0.1
* Apache Software Foundation Geronimo 1.0
* Apache Software Foundation Geronimo 2.1
* Apache Software Foundation Geronimo 2.0
* Apache Software Foundation Geronimo 1.2
* Apache Software Foundation Geronimo 1.1
* Apache Software Foundation Geronimo 1.0
* Apache Software Foundation Commons Daemon 1.0.6
Non-Vulnerable Systems:
* Apache Software Foundation Tomcat 5.5.34
* Apache Software Foundation Tomcat 7.0.20
* Apache Software Foundation Tomcat 6.0.33
* Apache Software Foundation Geronimo 2.1.8
* Apache Software Foundation Commons Daemon 1.0.7
Remote attackers can exploit this issue to gain access to files and directories owned by the superuser, through applications using the affected library. This allows attackers to obtain sensitive information that may aid in further attacks.
Versions prior to Commons Daemon 1.0.7 are vulnerable.
Vendor Status:
Apache Software Foundation as issued an update for this vulnerablity.
Patch Availability:
http://httpd.apache.org/download.cgi
CVE Information:
CVE-2011-2729
Disclosure Timeline:
Published:Aug 12 2011
Updated: Apr 17 2012
|
|
|
|
|