-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Fri, 18 Dec 2015 10:20:56 +0100 Source: tomcat8 Binary: tomcat8-common tomcat8 tomcat8-user libtomcat8-java libservlet3.1-java libservlet3.1-java-doc tomcat8-admin tomcat8-examples tomcat8-docs Architecture: source all Version: 8.0.14-1+deb8u1 Distribution: jessie-security Urgency: medium Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Emmanuel Bourg <ebourg@apache.org> Description: libservlet3.1-java - Servlet 3.1, JSP 2.3, EL 3.0 and WebSocket 1.0 Java API classes libservlet3.1-java-doc - Servlet 3.1, JSP 2.3, EL 3.0 and WebSocket 1.0 Java API documenta libtomcat8-java - Apache Tomcat 8 - Servlet and JSP engine -- core libraries tomcat8 - Apache Tomcat 8 - Servlet and JSP engine tomcat8-admin - Apache Tomcat 8 - Servlet and JSP engine -- admin web application tomcat8-common - Apache Tomcat 8 - Servlet and JSP engine -- common files tomcat8-docs - Apache Tomcat 8 - Servlet and JSP engine -- documentation tomcat8-examples - Apache Tomcat 8 - Servlet and JSP engine -- example web applicati tomcat8-user - Apache Tomcat 8 - Servlet and JSP engine -- tools to create user Changes: tomcat8 (8.0.14-1+deb8u1) jessie-security; urgency=medium . * Fixed CVE-2014-7810: Malicious web applications could use expression language to bypass the protections of a Security Manager as expressions were evaluated within a privileged code section. Checksums-Sha1: 8fdb845c8a4eaa99954304bb457e15ffcc51b356 2842 tomcat8_8.0.14-1+deb8u1.dsc a7e2dc9204fe9afd075c293edf50fb364d4e3026 3342416 tomcat8_8.0.14.orig.tar.xz d783d94d475440773ac7fa16bcbab5b742a16a25 39548 tomcat8_8.0.14-1+deb8u1.debian.tar.xz 7b5935e9fa32f92bf054e5a4a17dd828ce03d54e 54918 tomcat8-common_8.0.14-1+deb8u1_all.deb b6d0ddc9bfd1c7bcc0f3e0f50e4dec271e3e95fa 44148 tomcat8_8.0.14-1+deb8u1_all.deb 4db5110d7864f90ba6814c4395f864c93137f8c9 32066 tomcat8-user_8.0.14-1+deb8u1_all.deb 632f53ff16caf48b766113789a5d05bb5a05f666 4584846 libtomcat8-java_8.0.14-1+deb8u1_all.deb 78f75c57ef3ea8760bcbcf65822051c1bff40f25 389674 libservlet3.1-java_8.0.14-1+deb8u1_all.deb b2d97bde54c44a0cb75bac9b69f0cbe3469d5375 244670 libservlet3.1-java-doc_8.0.14-1+deb8u1_all.deb fd2d839dc52603fbb759cc9285a89ba043accfb3 33326 tomcat8-admin_8.0.14-1+deb8u1_all.deb 25d86e64acb3117339b79f70a11f8ed2e92622ce 191946 tomcat8-examples_8.0.14-1+deb8u1_all.deb fb6734e3bb7b5cb4c1ffb6b092ff43a9438d056a 685572 tomcat8-docs_8.0.14-1+deb8u1_all.deb Checksums-Sha256: 8aa9aeb58f1e737f6e54b5f859d80fd9911be30968cf1d9bef354f2e4af76435 2842 tomcat8_8.0.14-1+deb8u1.dsc 88a33409bf713882942cedfd41adb54e940060e625df532511d515b848f3460c 3342416 tomcat8_8.0.14.orig.tar.xz a7a36b5f700ce6043ac85f3ca0a843129ac7395343133d8a9b8dc493d9b23763 39548 tomcat8_8.0.14-1+deb8u1.debian.tar.xz ba38ed7fe91c339f40c7c6c308e3f382f26d4cd9aeb3a81d29e0386fe7dd94f3 54918 tomcat8-common_8.0.14-1+deb8u1_all.deb 59046381b73451a36e268625c0dde42f529fa66f18964ff26dd14bd1cd419b1f 44148 tomcat8_8.0.14-1+deb8u1_all.deb 42ed5aa08799de58e048792cc69371ccad27ac44ec930c5a00da0c602d827273 32066 tomcat8-user_8.0.14-1+deb8u1_all.deb ced303b3808110add4fab490e1593dfd2c3d88f150a597e13803625a4977181b 4584846 libtomcat8-java_8.0.14-1+deb8u1_all.deb 584c500dd798f6556f502feb9ddec4ab4a1cb2570d51a1b42c4af80d1f805857 389674 libservlet3.1-java_8.0.14-1+deb8u1_all.deb 12b06d186a2fab59fd119727a568385f0a8c3f8921a8b97bed9a15ca6f749b16 244670 libservlet3.1-java-doc_8.0.14-1+deb8u1_all.deb b7b0caa638194e7613bc7f5f6be7719ef5a0a4d136e4d1a6a792ad43ccafe1e8 33326 tomcat8-admin_8.0.14-1+deb8u1_all.deb 275ca0144bf841b430fba1ac95d12a759d6bc9725283515f1894c357d40b1ecc 191946 tomcat8-examples_8.0.14-1+deb8u1_all.deb 9a7361ace9ba97ddb36971d23feb49650f3ecadec654fc7a703dec4054c8fb69 685572 tomcat8-docs_8.0.14-1+deb8u1_all.deb Files: b8427a6a8e5f07cbd01007cec749d103 2842 java optional tomcat8_8.0.14-1+deb8u1.dsc 79b0e89d210ede119d2c6b47654cd6f1 3342416 java optional tomcat8_8.0.14.orig.tar.xz 49f864fc1b36e16afe2f4dfd53cb7e02 39548 java optional tomcat8_8.0.14-1+deb8u1.debian.tar.xz 2714c33c458e1133bc50510bf12827de 54918 java optional tomcat8-common_8.0.14-1+deb8u1_all.deb 555fd82db6e8f543b7a74f169bc5adfd 44148 java optional tomcat8_8.0.14-1+deb8u1_all.deb 994c66aa8a579a40b52c89fbef791f5c 32066 java optional tomcat8-user_8.0.14-1+deb8u1_all.deb 993f4498d4850cad8905afd9156d4831 4584846 java optional libtomcat8-java_8.0.14-1+deb8u1_all.deb 89d4314fa9aadb238247f0f3d6cc41e8 389674 java optional libservlet3.1-java_8.0.14-1+deb8u1_all.deb 82ae812cf02fe8ea537b098d41c0993a 244670 doc optional libservlet3.1-java-doc_8.0.14-1+deb8u1_all.deb 1c759e3d41021b5c2cb79546a7081bf4 33326 java optional tomcat8-admin_8.0.14-1+deb8u1_all.deb 8d6af8e85f0c0c291221336ca84e8dc6 191946 java optional tomcat8-examples_8.0.14-1+deb8u1_all.deb efea5cfcd0064e19f3ac2b6d3bd1743f 685572 doc optional tomcat8-docs_8.0.14-1+deb8u1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBAgAGBQJWdCcyAAoJEPUTxBnkudCsOdcQAIxLfpY30XKQm2wG4YUnxx1I s06CQAGk9tzyMGPQCstM95O0k5XtDlMLsHCrTGydd8OJVJbJGhPkeysw7gnVORRK /lwPddVSDQTeSnZ1gmHHvANTXPX6OHrnbM8KjcyngSgKLOBH0wQoJVnGTtdQ5mNn tx2hb7inplXNxOYmTlGOwizEv2e/KDdbvuAm15Cp9uXAkfUFyM6gxqipucN50xpQ fZtvDsoMJB9Gc0cikiii/7OxwnPDA2n/V16G4HwlCNnVib5oYPFswkSD7RjwLNgw 758sNwOwVNOPwQwJXUNUygbcd5a3XYsz+CH9j7NOj2wCYafxfve3bbMZykLKs9kU gpdAspw29u0Z/G22PPgbpfcfNrEvTZK+m/Doy8LjDOPYGrhnLR12bL/QHOPB+gdH Pz1QOyyyUnb7AVgGywFjf+8AYqlUoNMjnUEfrzBtYcT2GuIuOYFedofN56qm4qR/ sLVDi92K4nvfw3bzt6twsNWvMidNwv8nrK+TTBlIUl/BJfRLi3qua+jy03C3nwME EdS2w35gorCfrCTNJnbtXhKxBEPPrGkq4gjHEUaOc+PiPgncqs8EBHL46Mm1xn0D YJzVoHq7vMnQFhXcUajV6AgOT5LkfpK0hT5+yGbQcVEHpA4K21hHtSpgJddhy8g3 6J0TbeSjBrELUUngsdd0 =4hLJ -----END PGP SIGNATURE-----