CVE-2011-5062
Publication date 14 January 2012
Last updated 24 July 2024
Ubuntu priority
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
From the Ubuntu Security Team
sbeattie> MITRE split this out from CVE-2011-1184
Status
Package | Ubuntu Release | Status |
---|---|---|
tomcat5.5 | ||
tomcat6 | ||
tomcat7 | ||
Patch details
Package | Patch details |
---|---|
tomcat5.5 | |
tomcat6 | |
tomcat7 |