~ubuntu-branches/ubuntu/quantal/tomcat7/quantal-security

Viewing all changes in revision 23.

  • Committer: Package Import Robot
  • Author(s): Marc Deslauriers
  • Date: 2013-05-23 09:04:36 UTC
  • Revision ID: package-import@ubuntu.com-20130523090436-my67nl5mtyadx433
Tags: 7.0.30-0ubuntu1.2
* SECURITY UPDATE: FORM authentication request injection
  - debian/patches/CVE-2013-2067.patch: properly change session ID
    in java/org/apache/catalina/authenticator/FormAuthenticator.java.
  - CVE-2013-2067
* SECURITY UPDATE: information leak via AsyncListeners and
  RuntimeExceptions (LP: #1178645)
  - debian/patches/CVE-2013-2071.patch: catch RuntimeExceptions in
    java/org/apache/catalina/core/AsyncContextImpl.java, added tests to
    test/org/apache/catalina/core/TestAsyncContextImpl.java.
  - CVE-2013-2071
* Fix FTBFS due to expired test certificates:
  - d/keystores/*.jks: Newer keystores from upstream 7.0.39.
  - d/rules: Install newer keystores for testing, tidy up after use.
  - d/p/0018-update-test-certificates.patch: Cherry picked fixes from
    upstream VCS to update text based certificates.

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: