tomcat6 6.0.35-5ubuntu0.1 source package in Ubuntu

Changelog

tomcat6 (6.0.35-5ubuntu0.1) quantal-security; urgency=low

  [ Christian Kuersteiner ]
  * SECURITY UPDATE: denial of service via large header data
    - debian/patches/0012-CVE-2012-2733.patch: improve size logic in
      java/org/apache/coyote/http11/InternalNioInputBuffer.java.
    - CVE-2012-2733
    - LP: #1166649
  * SECURITY UPDATE: security-constraint bypass with FORM auth
    - debian/patches/CVE-2012-3546.patch: remove unneeded code in
      java/org/apache/catalina/realm/RealmBase.java.
    - CVE-2012-3546
  * SECURITY UPDATE: CSRF bypass via request with no session identifier
    - debian/patches/CVE-2012-4431.patch: check for session identifier in
      java/org/apache/catalina/filters/CsrfPreventionFilter.java.
    - CVE-2012-4431
  * SECURITY UPDATE: denial of service with NIO connector
    - debian/patches/CVE-2012-4534.patch: properly handle connection breaks
      in java/org/apache/tomcat/util/net/NioEndpoint.java.
    - CVE-2012-4534

  [ Jamie Strandboge ]
  * SECURITY UPDATE: multiple HTTP Digest Access Authentication flaws
    - debian/patches/0013-CVE-2012-588x.patch: disable caching of an
      authenticated user in the session by default, track server rather
      than client nonces, better handling of stale nonce values in
      java/org/apache/catalina/authenticator/DigestAuthenticator.java.
      Patch from Marc Deslauriers.
    - CVE-2012-3439
    - CVE-2012-5885
    - CVE-2012-5886
    - CVE-2012-5887
  * SECURITY UPDATE: denial of service via chunked transfer encoding
    - debian/patches/CVE-2012-3544.patch: properly parse CRLF in requests
      in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java.
      Patch from Marc Deslauriers.
    - CVE-2012-3544
  * SECURITY UPDATE: FORM authentication request injection
    - debian/patches/CVE-2013-2067.patch: properly change session ID
      in java/org/apache/catalina/authenticator/FormAuthenticator.java.
      Patch from Marc Deslauriers.
    - CVE-2013-2067
 -- Jamie Strandboge <email address hidden>   Tue, 28 May 2013 15:11:06 -0500

Upload details

Uploaded by:
Jamie Strandboge on 2013-05-28
Uploaded to:
Quantal
Original maintainer:
Ubuntu Developers
Architectures:
all
Section:
java
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Quantal: [FULLYBUILT] i386

Downloads

File Size SHA-256 Checksum
tomcat6_6.0.35.orig.tar.gz 3.1 MiB d348778396d7dde5c290c87d18464f9abc3b6d4d5e9a8e6ba13c4eddfebe6ab8
tomcat6_6.0.35-5ubuntu0.1.debian.tar.gz 53.0 KiB 5afe5f1d4666e731569bfb71aef01e6897d93fd42c0d449eadcea6a2e6be89b4
tomcat6_6.0.35-5ubuntu0.1.dsc 2.7 KiB 40778cbab3abea50c61d6d1ad4fb90efe86eb9ee33bf094e3b31f78dfcbe73bb

View changes file

Binary packages built by this source

libservlet2.4-java: No summary available for libservlet2.4-java in ubuntu quantal.

No description available for libservlet2.4-java in ubuntu quantal.

libservlet2.5-java: No summary available for libservlet2.5-java in ubuntu quantal.

No description available for libservlet2.5-java in ubuntu quantal.

libservlet2.5-java-doc: No summary available for libservlet2.5-java-doc in ubuntu quantal.

No description available for libservlet2.5-java-doc in ubuntu quantal.

libtomcat6-java: No summary available for libtomcat6-java in ubuntu quantal.

No description available for libtomcat6-java in ubuntu quantal.

tomcat6: No summary available for tomcat6 in ubuntu quantal.

No description available for tomcat6 in ubuntu quantal.

tomcat6-admin: No summary available for tomcat6-admin in ubuntu quantal.

No description available for tomcat6-admin in ubuntu quantal.

tomcat6-common: No summary available for tomcat6-common in ubuntu quantal.

No description available for tomcat6-common in ubuntu quantal.

tomcat6-docs: No summary available for tomcat6-docs in ubuntu quantal.

No description available for tomcat6-docs in ubuntu quantal.

tomcat6-examples: No summary available for tomcat6-examples in ubuntu quantal.

No description available for tomcat6-examples in ubuntu quantal.

tomcat6-extras: No summary available for tomcat6-extras in ubuntu quantal.

No description available for tomcat6-extras in ubuntu quantal.

tomcat6-user: No summary available for tomcat6-user in ubuntu quantal.

No description available for tomcat6-user in ubuntu quantal.