Bug#845425: Tomcat security update

2016-11-30 Thread Emmanuel Bourg
Le 30/11/2016 à 23:30, Markus Koschany a écrit : > Since I haven't heard anything yet I'm going to backport > ResourceLinkFactory.java as a precaution and release the security > announcement tomorrow. Sorry, I haven't spotted the cause of the regression yet. Emmanuel Bourg

Bug#845425: Tomcat security update

2016-11-30 Thread Markus Koschany
On 26.11.2016 17:00, Markus Koschany wrote: > On 22.11.2016 11:17, Emmanuel Bourg wrote: >> Three more CVEs have just been announced, a bit more serious this time : >> CVE-2016-6816 Apache Tomcat Information Disclosure >> CVE-2016-8735 Apache Tomcat Remote Code Execution >> CVE-2016-6817 Apache

Bug#845425: Tomcat security update

2016-11-26 Thread Markus Koschany
On 22.11.2016 11:17, Emmanuel Bourg wrote: > Three more CVEs have just been announced, a bit more serious this time : > CVE-2016-6816 Apache Tomcat Information Disclosure > CVE-2016-8735 Apache Tomcat Remote Code Execution > CVE-2016-6817 Apache Tomcat Denial of Service > > I'll prepare the sta