CVE-2011-4404

Publication date 19 November 2011

Last updated 24 July 2024


Ubuntu priority

The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified vectors, a related issue to CVE-2009-1523.

Read the notes from the security team

Status

Package Ubuntu Release Status
jetty 11.10 oneiric
Not affected
11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy
Not affected

Notes


tyhicks

There are few details at this point and it isn't clear if jetty in Ubuntu is affected or not. Debian marked this CVE as NOT-FOR-US


mdeslaur

looks like the bundled jetty in vsphere had not been fixed for CVE-2009-1523. Marking as not-affected.