what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Debian Security Advisory 3552-1

Debian Security Advisory 3552-1
Posted Apr 18, 2016
Authored by Debian | Site debian.org

Debian Linux Security Advisory 3552-1 - Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, which may result in information disclosure, the bypass of CSRF protections and bypass of the SecurityManager.

tags | advisory, vulnerability, info disclosure
systems | linux, debian
advisories | CVE-2015-5174, CVE-2015-5345, CVE-2015-5346, CVE-2015-5351, CVE-2016-0706, CVE-2016-0714, CVE-2016-0763
SHA-256 | 1b018da117488b19261b9d974ed2fe2088c108c4c83626583134bb1f11f147c8

Debian Security Advisory 3552-1

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3552-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
April 17, 2016 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : tomcat7
CVE ID : CVE-2015-5174 CVE-2015-5345 CVE-2015-5346 CVE-2015-5351
CVE-2016-0706 CVE-2016-0714 CVE-2016-0763

Multiple security vulnerabilities have been discovered in the Tomcat
servlet and JSP engine, which may result in information disclosure,
the bypass of CSRF protections and bypass of the SecurityManager.

For the oldstable distribution (wheezy), these problems have been fixed
in version 7.0.28-4+deb7u4. This update also fixes CVE-2014-0119 and
CVE-2014-0096.

For the stable distribution (jessie), these problems have been fixed in
version 7.0.56-3+deb8u2.

For the testing distribution (stretch), these problems have been fixed
in version 7.0.68-1.

For the unstable distribution (sid), these problems have been fixed in
version 7.0.68-1.

We recommend that you upgrade your tomcat7 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJXE9lQAAoJEBDCk7bDfE42StsP/jESeUXBDM54ZpOb0kH3C9YF
WAEDRlEtfBIjZW6HvO9aaUQYG/RICw41xTDaMixMZekdQTr3DUxkrdEVoLtjkj7q
UU6DRyDJYhYfsjvKp3GNusOdFm6eYNstkwViYGQCb8WyRb7tME4+J4AO68TzRKNE
BxBC/kPPxTLpt+J46vO9Phb8UlOhmVEM9QmZplsZDr+5KcRJkGFiK0O69GZ26MgT
lS8AxtOOw9vQF6lZWaOLlytGh8o/lhSRUI/vbZqytIAYH3YwS7sGTwtjgi2VFgrO
FVxa6xF98n2kT6RQdXXLWfHxh1gLH/O5NqNs4JGuMlwfXiLgJVWoFUMa9Nk3qXoy
e3xGzCdZizIGl6wlF89+/JL8XXCPZHABaQPGw5ZtILzpsLfdAdrCTcBBqk/t16yc
g33SgWyZva83WDc7S7mEo+CW5SXsbtyX+qT4F4mbWDYWF9JDRG6mnj/LCA/9Zu8z
PRdAFQxaue2tNkjwmlozuK+JPoje4lYJNyKo/Wxx6qNsfDAMcSdelFM4/pol0JPk
dUoUypoe6i2pOOAFX25aCUO3JMyqVKMdi7kheqKbAdCzaPxcCknvpi2fqOFPVVO7
YE0nUuQZpaYv1MWZLo7f+6Y1I3ncnTQFAoGKLaISvd7ghOAk2SpWeGRh7yCybbGw
jaHyZJXTIWz4qCAhpnb0
=GSUh
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    0 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close