This bug was fixed in the package tomcat5.5 - 5.5.25-5ubuntu1.3 --------------- tomcat5.5 (5.5.25-5ubuntu1.3) hardy-security; urgency=low
* SECURITY UPDATE: Apache Tomcat Authentication bypass and information disclosure (LP: #843701). - connectors/jk/java/org/apache/coyote/ajp/AjpAprProcessor.java: Prevent AJP request forgery via unread request body packet - upstream patch from Mark Thomas - http://svn.apache.org/viewvc?view=revision&revision=1162960 - CVE-2011-3190 -- James Page <james.p...@ubuntu.com> Mon, 26 Sep 2011 11:42:02 +0100 ** Changed in: tomcat5.5 (Ubuntu Hardy) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/843701 Title: CVE-2011-3190 Apache Tomcat Authentication bypass and information disclosure To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/tomcat5.5/+bug/843701/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs