~ubuntu-branches/ubuntu/precise/tomcat6/precise-updates

Viewing all changes in revision 50.

  • Committer: Package Import Robot
  • Author(s): Marc Deslauriers
  • Date: 2014-07-24 15:38:01 UTC
  • Revision ID: package-import@ubuntu.com-20140724153801-ye1h4zt8z9oijbm2
Tags: 6.0.35-1ubuntu3.5
* SECURITY UPDATE: denial of service via malformed chunk size
  - debian/patches/CVE-2014-0075.patch: fix overflow in
    java/org/apache/coyote/http11/filters/ChunkedInputFilter.java.
  - CVE-2014-0075
* SECURITY UPDATE: file disclosure via XXE issue
  - debian/patches/CVE-2014-0096.patch: change globalXsltFile to be a
    relative path in conf/web.xml,
    java/org/apache/catalina/servlets/DefaultServlet.java,
    java/org/apache/catalina/servlets/LocalStrings.properties,
    webapps/docs/default-servlet.xml.
  - CVE-2014-0096
* SECURITY UPDATE: HTTP request smuggling attack via crafted
  Content-Length HTTP header
  - debian/patches/CVE-2014-0099.patch: correctly handle long values in
    java/org/apache/tomcat/util/buf/Ascii.java.
  - CVE-2014-0099

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: