========================================================================== Ubuntu Security Notice USN-3787-1 October 10, 2018 tomcat7, tomcat8 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Tomcat could be made to redirect to arbitrary locations. Software Description: - tomcat8: Servlet and JSP engine - tomcat7: Servlet and JSP engine Details: It was discovered that Tomcat incorrectly handled returning redirects to a directory. A remote attacker could possibly use this issue with a specially crafted URL to redirect to arbitrary URIs. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: libtomcat8-java 8.0.32-1ubuntu1.8 tomcat8 8.0.32-1ubuntu1.8 Ubuntu 14.04 LTS: libtomcat7-java 7.0.52-1ubuntu0.16 tomcat7 7.0.52-1ubuntu0.16 In general, a standard system update will make all the necessary changes. References: https://usn.ubuntu.com/usn/usn-3787-1 CVE-2018-11784 Package Information: https://launchpad.net/ubuntu/+source/tomcat8/8.0.32-1ubuntu1.8 https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.16