what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Debian Security Advisory 3552-1

Debian Security Advisory 3552-1
Posted Apr 18, 2016
Authored by Debian | Site debian.org

Debian Linux Security Advisory 3552-1 - Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, which may result in information disclosure, the bypass of CSRF protections and bypass of the SecurityManager.

tags | advisory, vulnerability, info disclosure
systems | linux, debian
advisories | CVE-2015-5174, CVE-2015-5345, CVE-2015-5346, CVE-2015-5351, CVE-2016-0706, CVE-2016-0714, CVE-2016-0763
SHA-256 | 1b018da117488b19261b9d974ed2fe2088c108c4c83626583134bb1f11f147c8

Debian Security Advisory 3552-1

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3552-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
April 17, 2016 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : tomcat7
CVE ID : CVE-2015-5174 CVE-2015-5345 CVE-2015-5346 CVE-2015-5351
CVE-2016-0706 CVE-2016-0714 CVE-2016-0763

Multiple security vulnerabilities have been discovered in the Tomcat
servlet and JSP engine, which may result in information disclosure,
the bypass of CSRF protections and bypass of the SecurityManager.

For the oldstable distribution (wheezy), these problems have been fixed
in version 7.0.28-4+deb7u4. This update also fixes CVE-2014-0119 and
CVE-2014-0096.

For the stable distribution (jessie), these problems have been fixed in
version 7.0.56-3+deb8u2.

For the testing distribution (stretch), these problems have been fixed
in version 7.0.68-1.

For the unstable distribution (sid), these problems have been fixed in
version 7.0.68-1.

We recommend that you upgrade your tomcat7 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJXE9lQAAoJEBDCk7bDfE42StsP/jESeUXBDM54ZpOb0kH3C9YF
WAEDRlEtfBIjZW6HvO9aaUQYG/RICw41xTDaMixMZekdQTr3DUxkrdEVoLtjkj7q
UU6DRyDJYhYfsjvKp3GNusOdFm6eYNstkwViYGQCb8WyRb7tME4+J4AO68TzRKNE
BxBC/kPPxTLpt+J46vO9Phb8UlOhmVEM9QmZplsZDr+5KcRJkGFiK0O69GZ26MgT
lS8AxtOOw9vQF6lZWaOLlytGh8o/lhSRUI/vbZqytIAYH3YwS7sGTwtjgi2VFgrO
FVxa6xF98n2kT6RQdXXLWfHxh1gLH/O5NqNs4JGuMlwfXiLgJVWoFUMa9Nk3qXoy
e3xGzCdZizIGl6wlF89+/JL8XXCPZHABaQPGw5ZtILzpsLfdAdrCTcBBqk/t16yc
g33SgWyZva83WDc7S7mEo+CW5SXsbtyX+qT4F4mbWDYWF9JDRG6mnj/LCA/9Zu8z
PRdAFQxaue2tNkjwmlozuK+JPoje4lYJNyKo/Wxx6qNsfDAMcSdelFM4/pol0JPk
dUoUypoe6i2pOOAFX25aCUO3JMyqVKMdi7kheqKbAdCzaPxcCknvpi2fqOFPVVO7
YE0nUuQZpaYv1MWZLo7f+6Y1I3ncnTQFAoGKLaISvd7ghOAk2SpWeGRh7yCybbGw
jaHyZJXTIWz4qCAhpnb0
=GSUh
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close