tomcat-native 1.1.32~repack-2+deb8u1 source package in Debian

Changelog

tomcat-native (1.1.32~repack-2+deb8u1) jessie-security; urgency=high

  * Non-maintainer upload by the LTS.
  * Fix CVE-2017-15698:
    When parsing the AIA-Extension field of a client certificate, Apache Tomcat
    Native did not correctly handle fields longer than 127 bytes. The result of
    the parsing error was to skip the OCSP check. It was therefore possible for
    client certificates that should have been rejected (if the OCSP check had
    been made) to be accepted. Users not using OCSP checks are not affected by
    this vulnerability.

 -- Markus Koschany <email address hidden>  Sun, 11 Feb 2018 21:01:06 +0100

Upload details

Uploaded by:
Debian Java Maintainers
Uploaded to:
Jessie
Original maintainer:
Debian Java Maintainers
Architectures:
any
Section:
java
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section
Jessie release main java

Builds

Downloads

File Size SHA-256 Checksum
tomcat-native_1.1.32~repack-2+deb8u1.dsc 2.2 KiB 8bb6d7af9cd893cdc2fcb691e8951333aa6ff76d672051aadba5d9317ba20b87
tomcat-native_1.1.32~repack.orig.tar.gz 379.2 KiB 81394519aa0704f7fc6597148d9939fd2344bce4c9bbab0424050db2405b0cf5
tomcat-native_1.1.32~repack-2+deb8u1.debian.tar.xz 5.9 KiB 26ecddcde1b63d1c97319718d2b5d4c7cd2f46a8dd9a6ce25b8e478bc81a5aef

No changes file available.

Binary packages built by this source