|Description||Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.|
|Source||CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)|
|NVD severity||medium (attack range: remote)|
|Debian Bugs||532362, 532363, 532366|
Vulnerable and fixed packages
The table below lists information on source packages.
|tomcat6 (PTS)||wheezy (security), wheezy||6.0.45+dfsg-1~deb7u1||fixed|
|jessie (security), jessie||6.0.45+dfsg-1~deb8u1||fixed|
The information below is based on the following data on fixed versions.
[lenny] - tomcat6 <not-affected> (Only ships the servlet package)