[Bug 260016] Re: Update to Tomcat 6.0.18
Launchpad Bug Tracker
260016 at bugs.launchpad.net
Fri Aug 22 15:45:06 BST 2008
This bug was fixed in the package tomcat6 - 6.0.18-0ubuntu1
---------------
tomcat6 (6.0.18-0ubuntu1) intrepid; urgency=low
* New upstream version (LP: #260016)
- Fixes CVE-2008-2938: Directory traversal vulnerability (LP: #256802)
- Fixes CVE-2008-2370: Information disclosure vulnerability (LP: #256922)
- Fixes CVE-2008-1232: XSS through sendError vulnerability (LP: #256926)
* Dropped CVE-2008-1947.patch (fix is shipped in this upstream release)
* control: Improve short descriptions for the binary packages
* copyright: Added link to /usr/share/common-licenses/Apache-2.0
* control: To pull the right JRE, libtomcat6-java now depends on
default-jre-headless | java6-runtime-headless
-- Thierry Carrez <thierry.carrez at ubuntu.com> Fri, 22 Aug 2008
09:15:11 +0200
** Changed in: tomcat6 (Ubuntu)
Status: Confirmed => Fix Released
--
Update to Tomcat 6.0.18
https://bugs.launchpad.net/bugs/260016
You received this bug notification because you are a member of Ubuntu
Sponsors for universe, which is a direct subscriber.
More information about the Ubuntu-universe-sponsors
mailing list