[Bug 1178645] Re: tomcat7 needs update to 7.0.40
Launchpad Bug Tracker
1178645 at bugs.launchpad.net
Tue May 28 16:49:19 UTC 2013
This bug was fixed in the package tomcat7 - 7.0.30-0ubuntu1.2
---------------
tomcat7 (7.0.30-0ubuntu1.2) quantal-security; urgency=low
* SECURITY UPDATE: FORM authentication request injection
- debian/patches/CVE-2013-2067.patch: properly change session ID
in java/org/apache/catalina/authenticator/FormAuthenticator.java.
- CVE-2013-2067
* SECURITY UPDATE: information leak via AsyncListeners and
RuntimeExceptions (LP: #1178645)
- debian/patches/CVE-2013-2071.patch: catch RuntimeExceptions in
java/org/apache/catalina/core/AsyncContextImpl.java, added tests to
test/org/apache/catalina/core/TestAsyncContextImpl.java.
- CVE-2013-2071
* Fix FTBFS due to expired test certificates:
- d/keystores/*.jks: Newer keystores from upstream 7.0.39.
- d/rules: Install newer keystores for testing, tidy up after use.
- d/p/0018-update-test-certificates.patch: Cherry picked fixes from
upstream VCS to update text based certificates.
-- Marc Deslauriers <marc.deslauriers at ubuntu.com> Thu, 23 May 2013 09:04:36 -0400
** Changed in: tomcat7 (Ubuntu Quantal)
Status: Confirmed => Fix Released
** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-2067
** Changed in: tomcat7 (Ubuntu Raring)
Status: Confirmed => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to tomcat7 in Ubuntu.
https://bugs.launchpad.net/bugs/1178645
Title:
tomcat7 needs update to 7.0.40
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/tomcat7/+bug/1178645/+subscriptions
More information about the Ubuntu-server-bugs
mailing list