CVE-2012-2967: High severity Caucho Resin vulnerability
Caucho Quercus, as distributed in Resin before 4.0.29, does not properly implement the == (equals sign equals sign) operator for comparisons, which has unspecified impact and context-dependent attack vectors.
Other sources
Caucho Quercus, as distributed in Resin before 4.0.29, does not properly implement the == (equals sign equals sign) operator for comparisons, which has unspecified impact and context-dependent attack vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2967?
CVE-2012-2967 has an unspecified severity due to its context-dependent nature and the vague impact it can have.
How do I fix CVE-2012-2967?
To fix CVE-2012-2967, it's recommended to update to Caucho Resin version 4.0.29 or later.
What versions of Caucho Resin are affected by CVE-2012-2967?
CVE-2012-2967 affects all versions of Caucho Resin prior to 4.0.29.
What does CVE-2012-2967 vulnerability affect?
CVE-2012-2967 affects the implementation of the equality operator (==) in Caucho Quercus.
Is a workaround available for CVE-2012-2967?
No specific workaround is recommended for CVE-2012-2967; updating is the best course of action.