First published: Wed Jul 25 2018(Updated: )
It was discovered that Tomcat incorrectly handled decoding certain UTF-8 strings. A remote attacker could possibly use this issue to cause Tomcat to crash, resulting in a denial of service. (CVE-2018-1336) It was discovered that the Tomcat WebSocket client incorrectly performed hostname verification. A remote attacker could possibly use this issue to intercept sensitive information. (CVE-2018-8034)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libtomcat8-java | <8.0.32-1ubuntu1.7 | 8.0.32-1ubuntu1.7 |
Ubuntu OpenSSH Client | =16.04 | |
All of | ||
ubuntu/tomcat8 | <8.0.32-1ubuntu1.7 | 8.0.32-1ubuntu1.7 |
Ubuntu OpenSSH Client | =16.04 | |
All of | ||
ubuntu/libtomcat7-java | <7.0.52-1ubuntu0.15 | 7.0.52-1ubuntu0.15 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/tomcat7 | <7.0.52-1ubuntu0.15 | 7.0.52-1ubuntu0.15 |
Ubuntu OpenSSH Client | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-3723-1 is the identifier for a security advisory released by Ubuntu that addresses vulnerabilities in Tomcat.
The severity of CVE-2018-1336 is not specified in the provided information.
CVE-2018-1336 can cause Tomcat to crash, resulting in a denial of service.
Versions 8.0.32-1ubuntu1.7 and earlier of libtomcat8-java and tomcat8, as well as versions 7.0.52-1ubuntu0.15 and earlier of libtomcat7-java and tomcat7, are affected by USN-3723-1.
To fix the vulnerabilities, update the affected versions of libtomcat8-java, tomcat8, libtomcat7-java, and tomcat7 to versions 8.0.32-1ubuntu1.7, 7.0.52-1ubuntu0.15, 8.0.32-1ubuntu1.7, and 7.0.52-1ubuntu0.15 respectively.