CVE-2013-0346
Publication date 15 February 2014
Last updated 24 July 2024
Ubuntu priority
** DISPUTED ** Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."
Status
Package | Ubuntu Release | Status |
---|---|---|
tomcat5.5 | ||
tomcat6 | ||
tomcat7 | ||
Notes
jdstrand
/var/log/tomcat5.5 is 750 on Ubuntu 8.04 LTS /var/log/tomcat6 is 750 on Ubuntu 10.04 LTS10 and higher /var/log/tomcat7 is 750 on Ubuntu 11.10 and higher