Ubuntu 7242-1: Tomcat Security Advisory Updates
Summary
A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Tomcat could be made to run programs if it received specially crafted network traffic. Software Description: - tomcat6: Servlet and JSP engine Details: Pierre Ernst discovered that the Tomcat JmxRemoteLifecycleListener did not implement a recommended fix. A remote attacker could possibly use this issue to execute arbitrary code.
Update Instructions
The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS libservlet2.5-java 6.0.39-1ubuntu0.1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
References
https://ubuntu.com/security/notices/USN-7242-1
CVE-2016-8735
Package Information