~ubuntu-branches/ubuntu/precise/tomcat6/precise-security

Viewing all changes in revision 46.

  • Committer: Package Import Robot
  • Author(s): Marc Deslauriers
  • Date: 2012-11-21 10:36:18 UTC
  • Revision ID: package-import@ubuntu.com-20121121103618-gbv5unu2ecjzm72i
Tags: 6.0.35-1ubuntu3.1
* SECURITY UPDATE: denial of service via large header data
  - debian/patches/0012-CVE-2012-2733.patch: improve size logic in
    java/org/apache/coyote/http11/InternalNioInputBuffer.java.
  - CVE-2012-2733
* SECURITY UPDATE: multiple HTTP Digest Access Authentication flaws
  - debian/patches/0013-CVE-2012-588x.patch: disable caching of an
    authenticated user in the session by default, track server rather
    than client nonces, better handling of stale nonce values in
    java/org/apache/catalina/authenticator/DigestAuthenticator.java.
  - CVE-2012-3439
  - CVE-2012-5885
  - CVE-2012-5886
  - CVE-2012-5887

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: