Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 636132 (CVE-2017-12617) - www-servers/tomcat: Imcomplete fix Remote Code Execution Vulneratiliby (CVE-2017-12617)
Summary: www-servers/tomcat: Imcomplete fix Remote Code Execution Vulneratiliby (CVE-...
Alias: CVE-2017-12617
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
Whiteboard: C2 [ebuild cve]
Depends on:
Reported: 2017-11-01 06:10 UTC by GLSAMaker/CVETool Bot
Modified: 2019-03-27 00:14 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2017-11-01 06:10:22 UTC
CVE-2017-12617 (
  When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22,
  8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via
  setting the readonly initialisation parameter of the Default servlet to
  false) it was possible to upload a JSP file to the server via a specially
  crafted request. This JSP could then be requested and any code it contained
  would be executed by the server.
Comment 1 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-11-01 06:12:10 UTC
@Maintainers could you confirm if we are affected by this CVE? Please call for stabilization when ready if that's the case.

Thank you
Comment 2 Miroslav Šulc gentoo-dev 2017-11-16 08:57:07 UTC
i cleaned tomcat so that it contains only the latest releases:

$ PORTDIR=/usr/src/gentoo.git/ equery meta tomcat
 * www-servers/tomcat [gentoo]
Maintainer: (Java)
Upstream:    None specified
Location:    /usr/src/gentoo.git/www-servers/tomcat
Keywords:    7.0.82:7: amd64 ~amd64-linux ~ppc64 ~x86 ~x86-linux ~x86-solaris
Keywords:    8.0.47:8: amd64 ~amd64-linux ~x86 ~x86-fbsd ~x86-linux ~x86-solaris
Keywords:    8.5.23:8.5: amd64 ~amd64-linux ~x86 ~x86-fbsd ~x86-linux ~x86-solaris
Keywords:    9.0.1_beta:9: ~amd64 ~amd64-linux ~x86 ~x86-fbsd ~x86-linux ~x86-solaris
License:     Apache-2.0

we agreed that x86 will be dropped to ~x86 as its usage is declining