Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2013-4444

Publication date 12 September 2014

Last updated 24 July 2024


Ubuntu priority

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.

Read the notes from the security team

Status

Package Ubuntu Release Status
tomcat7 17.04 zesty
Not affected
16.10 yakkety
Not affected
16.04 LTS xenial
Not affected
15.10 wily
Not affected
15.04 vivid
Not affected
14.10 utopic
Not affected
14.04 LTS trusty
Not affected
12.04 LTS precise Ignored
10.04 LTS lucid Not in release

Notes


jdstrand

per upstream, 7.0.0 to 7.0.39


mdeslaur

This is the same issue as CVE-2013-2185 issued by Red Hat