Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 636132 (CVE-2017-12617)

Summary: www-servers/tomcat: Imcomplete fix Remote Code Execution Vulneratiliby (CVE-2017-12617)
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED OBSOLETE    
Severity: normal CC: java
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://lists.apache.org/thread.html/3fd341a604c4e9eab39e7eaabbbac39c30101a022acc11dd09d7ebcb@%3Cannounce.tomcat.apache.org%3E
Whiteboard: C2 [ebuild cve]
Package list:
Runtime testing required: ---

Description GLSAMaker/CVETool Bot gentoo-dev 2017-11-01 06:10:22 UTC
CVE-2017-12617 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12617):
  When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22,
  8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via
  setting the readonly initialisation parameter of the Default servlet to
  false) it was possible to upload a JSP file to the server via a specially
  crafted request. This JSP could then be requested and any code it contained
  would be executed by the server.
Comment 1 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-11-01 06:12:10 UTC
@Maintainers could you confirm if we are affected by this CVE? Please call for stabilization when ready if that's the case.

Thank you
Comment 2 Miroslav Šulc gentoo-dev 2017-11-16 08:57:07 UTC
i cleaned tomcat so that it contains only the latest releases:

$ PORTDIR=/usr/src/gentoo.git/ equery meta tomcat
 * www-servers/tomcat [gentoo]
Maintainer:  java@gentoo.org (Java)
Upstream:    None specified
Homepage:    http://tomcat.apache.org/
Location:    /usr/src/gentoo.git/www-servers/tomcat
Keywords:    7.0.82:7: amd64 ~amd64-linux ~ppc64 ~x86 ~x86-linux ~x86-solaris
Keywords:    8.0.47:8: amd64 ~amd64-linux ~x86 ~x86-fbsd ~x86-linux ~x86-solaris
Keywords:    8.5.23:8.5: amd64 ~amd64-linux ~x86 ~x86-fbsd ~x86-linux ~x86-solaris
Keywords:    9.0.1_beta:9: ~amd64 ~amd64-linux ~x86 ~x86-fbsd ~x86-linux ~x86-solaris
License:     Apache-2.0

we agreed that x86 will be dropped to ~x86 as its usage is declining