[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 1301-1] tomcat7 security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Package        : tomcat7
Version        : 7.0.28-4+deb7u18
CVE ID         : CVE-2018-1304 CVE-2018-1305

Two security vulnerabilities have been discovered in the Tomcat
servlet and JSP engine.

CVE-2018-1304
    The URL pattern of "" (the empty string) which exactly maps to the
    context root was not correctly handled in Apache Tomcat when used
    as part of a security constraint definition. This caused the
    constraint to be ignored. It was, therefore, possible for
    unauthorized users to gain access to web application resources that
    should have been protected. Only security constraints with a URL
    pattern of the empty string were affected.

CVE-2018-1305
    Security constraints defined by annotations of Servlets in Apache
    Tomcat were only applied once a Servlet had been loaded. Because
    security constraints defined in this way apply to the URL pattern
    and any URLs below that point, it was possible - depending on the
    order Servlets were loaded - for some security constraints not to be
    applied. This could have exposed resources to users who were not
    authorized to access them.

For Debian 7 "Wheezy", these problems have been fixed in version
7.0.28-4+deb7u18.

We recommend that you upgrade your tomcat7 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlqelppfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD
RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7
UeRSxQ//Yk+TVTeaQIK24y7mXihfHMxCx6Uqn9i0M89QMpe/J+Ej3IOSWG2Bh8Kn
UiPFXt6Lg3jtNodaIOzki8v5f7IbCTF3Xvt+r1N2jW3sO1YC3mdxjvmhB7/fJYz+
MUxN3KosLf0y6d7ePideGFwogFPB6nTHHYYgPdtz4MmhFmZrLo/PAcQZOQofuJMV
X18Iy+1fboVvQNn/VJxiMFmsGSVEYO3tk0kIorkvajh8JCHHVGgNK2tQTF3PYKH+
IcVh9bVxakxwtISMayMHC5nRBEcN266bQoS2IeWyv7hLGUbN3gES3ILYXPKOl0Oo
94AZMqEzC1KcsLK21kxvnK1gJtaH8NsVcBFuL/arZvtPv69XBJ1MljSFdocAIfZC
5wBSi/L5xPjfalnLxWE30MEfaJqeANv4+laEjoSupZgioIKIgUuHQSGaXiOKY/Xr
n+HsOa21jq2cEYu3t2Xp8wW9hj07PESE2xG77dIf2r0OYTI/W8lshLOoiMJjEbcP
KIrFeU09IOPqRYy7mPsqZMpWpD9TovfL3AI6+4q2zqH4VO22Wb2NIVKsCeGjwg10
LnQU20dPZtttTqmPzTGuPNPT2uPWg9t8P5A3t4ovH7Kb2tFPbOmjowWWQHr3tdaJ
niFP40TsW42G5hHn7d9onM//Ah7uQxoVfz9Qgmy5qKFK+iUUNk0=
=IOFr
-----END PGP SIGNATURE-----


Reply to: