~ubuntu-branches/ubuntu/lucid/tomcat6/lucid-security

Viewing all changes in revision 25.

  • Committer: Package Import Robot
  • Author(s): Marc Deslauriers
  • Date: 2012-11-21 10:44:41 UTC
  • Revision ID: package-import@ubuntu.com-20121121104441-8cyr7frbxdvpq5mm
Tags: 6.0.24-2ubuntu1.11
* SECURITY UPDATE: denial of service via large header data
  - debian/patches/0012-CVE-2012-2733.patch: improve size logic in
    java/org/apache/coyote/http11/InternalNioInputBuffer.java.
  - CVE-2012-2733
* SECURITY UPDATE: multiple HTTP Digest Access Authentication flaws
  - debian/patches/0013-CVE-2012-588x.patch: disable caching of an
    authenticated user in the session by default, track server rather
    than client nonces, better handling of stale nonce values in
    java/org/apache/catalina/authenticator/DigestAuthenticator.java.
  - CVE-2012-3439
  - CVE-2012-5885
  - CVE-2012-5886
  - CVE-2012-5887

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: