-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3614-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 02, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : tomcat7 CVE ID : CVE-2016-3092 The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it easy to add robust, high-performance, file upload capability to servlets and web applications. A remote attacker can take advantage of this flaw by sending file upload requests that cause the HTTP server using the Apache Commons Fileupload library to become unresponsive, preventing the server from servicing other requests. Apache Tomcat uses a package renamed copy of Apache Commons FileUpload to implement the file upload requirements of the Servlet specification and is therefore also vulnerable to the denial of service vulnerability. For the stable distribution (jessie), this problem has been fixed in version 7.0.56-3+deb8u3. For the testing distribution (stretch), this problem has been fixed in version 7.0.70-1. For the unstable distribution (sid), this problem has been fixed in version 7.0.70-1. We recommend that you upgrade your tomcat7 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJXd7YhAAoJEAVMuPMTQ89Emg0P/2K7qVBmKMDG93HhWe2e5QXk I748PwHm7uHV5qrIYGS8n1LDhqNxOyMaGVJdHzJAvuOJYOVsq2RXLXAhNSNZLPgr mrOCB6i6u1ogY9ztsQi5zprhl6v0AINpQA1pP30COmiS/QlUUbGV09Z952Gg/d25 JDEpvkDmiknAKySP8Jm3GjqhYnJdyOnkRpT/PyJCfepBFk2ToR0HHOPw7kSxkCFV SM8E0ljjrZZVKQ5SRD18egi5VjnV7R/pm+MuejfdtdA+eA/UsrUeQH0kVWNN8LUP Hfry2Dz11tAi8WfdP9nc4cPm9m1XLG4S64J3ZwwUNzyuxYXpkyzKIViQDuO4WHMR vKZpUjYuRcSGqySdhN2HdYxgZET3avO20tN39+iH2ASuv5LDZJ6tOQXX713+Xox1 988nMEDkxIWbgPgfIhEhPIRoW8efEAczHoY80XxjAPJF9PokCqN5OjFBQPS60D3z zycu8+Hrxlx3C8emkVElDaFeyTmWYrMxJ/yEBEN+m0dhMdbzcwlXTAtLgrXkQUga Ly8RmMpougmN0Kx0CqCwYKyxzn7peSi2LP90gfHu5etks3rtN122c2R69Ma1DbXh mEMj0K9R2qjKFJeZ9fIU7Gxx9+Wo0dJnlEMc3jL2Ne36HBrcP3fQuKnQxw2lWbaP yL3atzZ13OmvyxAJltuN =RBqU -----END PGP SIGNATURE-----