-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 23 Dec 2019 22:40:00 +0100 Source: tomcat8 Binary: tomcat8-common tomcat8 tomcat8-user libtomcat8-java libtomcat8-embed-java libservlet3.1-java libservlet3.1-java-doc tomcat8-admin tomcat8-examples tomcat8-docs Architecture: source all Version: 8.5.50-0+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: libservlet3.1-java - Servlet 3.1, JSP 2.3, EL 3.0 and WebSocket 1.0 Java API classes libservlet3.1-java-doc - Servlet 3.1, JSP 2.3, EL 3.0 and WebSocket 1.0 Java API documenta libtomcat8-embed-java - Apache Tomcat 8 - Servlet and JSP engine -- embed libraries libtomcat8-java - Apache Tomcat 8 - Servlet and JSP engine -- core libraries tomcat8 - Apache Tomcat 8 - Servlet and JSP engine tomcat8-admin - Apache Tomcat 8 - Servlet and JSP engine -- admin web application tomcat8-common - Apache Tomcat 8 - Servlet and JSP engine -- common files tomcat8-docs - Apache Tomcat 8 - Servlet and JSP engine -- documentation tomcat8-examples - Apache Tomcat 8 - Servlet and JSP engine -- example web applicati tomcat8-user - Apache Tomcat 8 - Servlet and JSP engine -- tools to create user Changes: tomcat8 (8.5.50-0+deb9u1) stretch-security; urgency=high . * Team upload. * Fix CVE-2018-11784, CVE-2018-8014, CVE-2019-0199, CVE-2019-0221, CVE-2019-12418, CVE-2019-17563. Several security vulnerabilities were found in Tomcat 8 that may lead to denial-of-service or local privilege escalation. Checksums-Sha1: 3bd2221335dc305b8663ad68f30903d1c485f228 3101 tomcat8_8.5.50-0+deb9u1.dsc 6c971c1fb42d7dcda51e636269eae1cd887beeb6 3752812 tomcat8_8.5.50.orig.tar.xz 64a549160cc3c29a4cd03389d40fe4c297c55416 42872 tomcat8_8.5.50-0+deb9u1.debian.tar.xz 2cc414fc43c73a6d097c9122fdd7444bae2fea00 242818 libservlet3.1-java-doc_8.5.50-0+deb9u1_all.deb d8bb482e2570150ec9fdf7ecb55112204d8fb0d4 402968 libservlet3.1-java_8.5.50-0+deb9u1_all.deb 92d60de9c79406b518c951fbf51f8225ab4a2409 4081948 libtomcat8-embed-java_8.5.50-0+deb9u1_all.deb 797d8f6bdac9252e2285c06c2d9c4b0805a3343e 5336294 libtomcat8-java_8.5.50-0+deb9u1_all.deb f51d2b36a6793f6cdd9b1e23269193466af1525a 32060 tomcat8-admin_8.5.50-0+deb9u1_all.deb 7b16fd17347eebbe2663f3ed1dce3572c619b70a 66292 tomcat8-common_8.5.50-0+deb9u1_all.deb 17218cb476fa467e308788fa1927c736455883fc 686674 tomcat8-docs_8.5.50-0+deb9u1_all.deb d7debf9cf706563debd54ace6a72403f33575df0 188864 tomcat8-examples_8.5.50-0+deb9u1_all.deb 8311e265793fba1747dc05c72267f014ea1d06a3 40426 tomcat8-user_8.5.50-0+deb9u1_all.deb e29a878fe7f2a501c53f3198c306d6f5e198c760 52558 tomcat8_8.5.50-0+deb9u1_all.deb 9e44ebfa71b856c0b628d208443b59943845977a 14623 tomcat8_8.5.50-0+deb9u1_amd64.buildinfo Checksums-Sha256: f075fda8a0f1bede1c5b18700707dfb1093ca7a0780cacf624e2339d10f4d4fd 3101 tomcat8_8.5.50-0+deb9u1.dsc 0aaac8193ab2ad5372be51e3d037c2ad391b3f2d88c7cab26f7cc70e570d7146 3752812 tomcat8_8.5.50.orig.tar.xz 3585eb35fd6e232909d0af1fec4e52dd9b5eb9ef944f64ae24b32d610295c98d 42872 tomcat8_8.5.50-0+deb9u1.debian.tar.xz ea2e890b21d9ffd77470a86120cecb5b78cf182964935bf5044b6f80d7c93f12 242818 libservlet3.1-java-doc_8.5.50-0+deb9u1_all.deb 8454e4a3b780ce01e7b2026cdad861a2a4d561be8dbf3d22631a184f08887ad4 402968 libservlet3.1-java_8.5.50-0+deb9u1_all.deb 339c2e6cbd0f407070fb62520c54bcd15be1e79dc552cd02557ad3381280a112 4081948 libtomcat8-embed-java_8.5.50-0+deb9u1_all.deb 05c8d1accf4ed2dd4c7c8bef4017e9a4424f7905cab231f9e64aa567d1b5e445 5336294 libtomcat8-java_8.5.50-0+deb9u1_all.deb 63bb259a6df09e301b1179a077f2627e2a97f5ae8d79d2f1323c425fa6db9add 32060 tomcat8-admin_8.5.50-0+deb9u1_all.deb 3d3d597aa179eb6c4eb1e58a6a9726afa16ae167b002e4b90c626e3d00666076 66292 tomcat8-common_8.5.50-0+deb9u1_all.deb 28b1e5fa0fdb29672604945e888ca3e6a985c3c2f69382b44a965f14914877c1 686674 tomcat8-docs_8.5.50-0+deb9u1_all.deb 217efe7624b76da35e05e4f0cc927ac5f57ab3b3df0bec6ca8d8dacf80f00db5 188864 tomcat8-examples_8.5.50-0+deb9u1_all.deb e0dd96c0fe2d7a80b529da6dc49bff7b500a7e08685250bd2ed62d78be6e4e3c 40426 tomcat8-user_8.5.50-0+deb9u1_all.deb c698997b159bf9ba1771f8aa789bb914f140c625103b4ce967d4a5bc4e6e904c 52558 tomcat8_8.5.50-0+deb9u1_all.deb 6533a2a19f13941bb73ef419f9bfdbbf6cb964f74a330eb76ab8d956a40935dc 14623 tomcat8_8.5.50-0+deb9u1_amd64.buildinfo Files: c81a186ab9f979c847980ebd688fd004 3101 java optional tomcat8_8.5.50-0+deb9u1.dsc a2f087c1f84c62eb5502166999c0d4a8 3752812 java optional tomcat8_8.5.50.orig.tar.xz 696e13ff4ef6991390701609d724fb94 42872 java optional tomcat8_8.5.50-0+deb9u1.debian.tar.xz 2c2d34aaa97e8819b2d1f1dd2150234b 242818 doc optional libservlet3.1-java-doc_8.5.50-0+deb9u1_all.deb c39277f21c4fae6a4168e5738eac6b2c 402968 java optional libservlet3.1-java_8.5.50-0+deb9u1_all.deb 891beb861e53553439849dff57fd2e7e 4081948 java optional libtomcat8-embed-java_8.5.50-0+deb9u1_all.deb 57d56b6be0f73544c2ead550d7936d67 5336294 java optional libtomcat8-java_8.5.50-0+deb9u1_all.deb cf78b664eecf805e06d20d64b8f97e41 32060 java optional tomcat8-admin_8.5.50-0+deb9u1_all.deb c3a5fdbfe207c3cda9f8803184460420 66292 java optional tomcat8-common_8.5.50-0+deb9u1_all.deb e5edd968f750bae0981e28a69788b047 686674 doc optional tomcat8-docs_8.5.50-0+deb9u1_all.deb ba230ff6aadc0e06fdcef2f34d58843d 188864 java optional tomcat8-examples_8.5.50-0+deb9u1_all.deb 1412d1c1f8f00a086de32c44ae584eb4 40426 java optional tomcat8-user_8.5.50-0+deb9u1_all.deb 0ae260e6e4131d54550f1b202d3062c7 52558 java optional tomcat8_8.5.50-0+deb9u1_all.deb d9a4b8b2f362777a9b10cd0a47bb5bb5 14623 java optional tomcat8_8.5.50-0+deb9u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl4BNgFfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1Hkji8QALK1Zh2ytZOXFZQlmecTDIi93kLnDWplee79 3hg5Sio5FgUcufi7SpPVllBLl+7cFiQgvaZvgzjlpRCCOr5MvlM17KSx6J5UGud5 Ebjb05/wVDkr8CK4YwFT9L3mMRCg6TAO8nttzYMZSYZifBQqrWQqKgLFzY6CUjQW VAQ6pQ3ZZKvGgZkulr5L4SUHAcjxK5xNJB12Bg6SleHJ0/X5nF+1HWF2ImDGc6Jj BD2+ntdEl0g57SAbjPA2x8Z+95p6fuyUMLrS2XlGnaDA2RbxNE5RDSIdzOIINzXq 4oe7YAMtuzW1QDRYKGBGxzkPFMBXv+mLwGBsA72FBB1gBdG19U929pi847w/QkTN pfrEq1t0TiHEidkuCuXUHx5edqKMphyJdZOMUteYKhBBaY0Ru78WSS96m9cv6cJJ r8T8yy6Rzscp4xE/OKuU0li3DPOrDYpYCGNTmk8SRaY1tDP6W6cEypyvR/fDSaN0 mChkuhO26DiJ+GJK1HSMn/wKsraMyhJ2HEcC0zT6wqO+X7L9h39Lf+Q2gFLeQmeb 0yAvwSUTkINOlNY6711PgJABMkR+HtbaHhnf2YTRQR9WPxMYlCUAVdj4QWauMEWS Ign0fJ97AgQpOMwRE7RxMBiUnH4u38v712kpG7LPiqGcdvGLtemZwzj9fTK4EGDt 4s6vLfw4 =eEoy -----END PGP SIGNATURE-----