CVE-2011-1184
Publication date 26 September 2011
Last updated 24 July 2024
Ubuntu priority
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.
Status
Package | Ubuntu Release | Status |
---|---|---|
tomcat5.5 | ||
tomcat6 | ||
tomcat7 | ||
Patch details
Package | Patch details |
---|---|
tomcat6 |
References
Related Ubuntu Security Notices (USN)
- USN-1252-1
- Tomcat vulnerabilities
- 8 November 2011