Security update for tomcat5

SUSE Security Update: Security update for tomcat5
Announcement ID: SUSE-SU-2012:0144-1
Rating: moderate
References: #727543
Affected Products:
  • SUSE Linux Enterprise Server 10 SP4
  • SLE SDK 10 SP4

  • An update that fixes one vulnerability is now available.

    Description:


    This security update for tomcat5 fixes a vulnerability to a
    hash collision attack which allows remote attackers to
    perform denial of service attacks. The issue is tracked as
    CVE-2011-4858
    > .

    Indications:

    Everyone using Apache Tomcat should update.

    Package List:

    • SUSE Linux Enterprise Server 10 SP4 (noarch):
    • tomcat5-5.5.27-0.18.4
    • tomcat5-admin-webapps-5.5.27-0.18.4
    • tomcat5-webapps-5.5.27-0.18.4
    • SLE SDK 10 SP4 (noarch):
    • tomcat5-5.5.27-0.18.4
    • tomcat5-admin-webapps-5.5.27-0.18.4
    • tomcat5-webapps-5.5.27-0.18.4

    References:

    • http://support.novell.com/security/cve/CVE-2011-4858.html
    • https://bugzilla.novell.com/727543
    • http://download.suse.com/patch/finder/?keywords=db53da1f9bc372bf81229767487059b1