Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2013-4444

Published: 12 September 2014

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.

Notes

AuthorNote
jdstrand
per upstream, 7.0.0 to 7.0.39
mdeslaur
This is the same issue as CVE-2013-2185 issued by Red Hat

Priority

Medium

Status

Package Release Status
tomcat7
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Ignored
(end of life)
trusty Not vulnerable
(7.0.52-1ubuntu0.1)
upstream
Released (7.0.40-1)
utopic Not vulnerable

vivid Not vulnerable

wily Not vulnerable

xenial Not vulnerable

yakkety Not vulnerable

zesty Not vulnerable