CVE-2011-5062
Publication date 14 January 2012
Last updated 24 July 2024
Ubuntu priority
Description
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.
From the Ubuntu Security Team
sbeattie> MITRE split this out from CVE-2011-1184
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| tomcat5.5 | ||
| tomcat6 | ||
| tomcat7 | ||
Patch details
| Package | Patch details |
|---|---|
| tomcat5.5 | |
| tomcat6 | |
| tomcat7 |