-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 05 Jan 2017 18:15:56 +0100 Source: tomcat7 Binary: tomcat7-common tomcat7 tomcat7-user libtomcat7-java libservlet3.0-java libservlet3.0-java-doc tomcat7-admin tomcat7-examples tomcat7-docs Architecture: source all Version: 7.0.56-3+deb8u7 Distribution: jessie-security Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Emmanuel Bourg <ebourg@apache.org> Description: libservlet3.0-java - Servlet 3.0 and JSP 2.2 Java API classes libservlet3.0-java-doc - Servlet 3.0 and JSP 2.2 Java API documentation libtomcat7-java - Servlet and JSP engine -- core libraries tomcat7 - Servlet and JSP engine tomcat7-admin - Servlet and JSP engine -- admin web applications tomcat7-common - Servlet and JSP engine -- common files tomcat7-docs - Servlet and JSP engine -- documentation tomcat7-examples - Servlet and JSP engine -- example web applications tomcat7-user - Servlet and JSP engine -- tools to create user instances Changes: tomcat7 (7.0.56-3+deb8u7) jessie-security; urgency=high . * Fixed CVE-2016-8745: A bug in the error handling of the send file code for the NIO HTTP connector resulted in the current Processor object being added to the Processor cache multiple times. This in turn meant that the same Processor could be used for concurrent requests. Sharing a Processor can result in information leakage between requests including, not not limited to, session ID and the response body. Checksums-Sha1: ee3c88eea703cfcf5ba0c0c7621238d230b8fe4b 2758 tomcat7_7.0.56-3+deb8u7.dsc 04ed5a8d7562fd6c6d7c4ec9cd2a079128464ff3 90340 tomcat7_7.0.56-3+deb8u7.debian.tar.xz 041a22d013b9bcdfc47476bc04775eb9d60628a5 63770 tomcat7-common_7.0.56-3+deb8u7_all.deb f07b4201a465a42b5d855364a49a0e9a9733014b 52598 tomcat7_7.0.56-3+deb8u7_all.deb 1b0d1fbb13c35722ec268077b550885bb424738e 40080 tomcat7-user_7.0.56-3+deb8u7_all.deb e032c1f407c36ef0238062c4bd1c3becd2b5af51 3629086 libtomcat7-java_7.0.56-3+deb8u7_all.deb 8e99a5e56fd40f240f91f7780b91ba8f3dad08c2 316016 libservlet3.0-java_7.0.56-3+deb8u7_all.deb 43f4dfeb76e0b7f32518239bea814b2e81720f20 206334 libservlet3.0-java-doc_7.0.56-3+deb8u7_all.deb e11ee3db429eaea1b9b218d611fb3459a005b44f 41076 tomcat7-admin_7.0.56-3+deb8u7_all.deb 51434d6a226cda416708c472bfebd5d2a6df67b8 199238 tomcat7-examples_7.0.56-3+deb8u7_all.deb a49f5f964a2cd85f06bd983dcf38c39baf78cdc9 605872 tomcat7-docs_7.0.56-3+deb8u7_all.deb Checksums-Sha256: 34918213cdbaede3a867bbaa2081828ef8c714e4d66347ba52da4d737b3046ab 2758 tomcat7_7.0.56-3+deb8u7.dsc ec26805e2f2c0c4e3a51c21d44572a8552462041d952026badd21557641096dd 90340 tomcat7_7.0.56-3+deb8u7.debian.tar.xz 1f41d998f3b15ad8fea55385851f614a7aab3b93886e9541e9e5da74b125bde2 63770 tomcat7-common_7.0.56-3+deb8u7_all.deb fe81d57c3d3764351e84fb3bc25f8dfe65ad7fac7b22ca1fff62d2f9585610ca 52598 tomcat7_7.0.56-3+deb8u7_all.deb 8886a70e36fff57b18ef95b1670b85dc0f60bfc2154b89ecfb569f18644ae3e6 40080 tomcat7-user_7.0.56-3+deb8u7_all.deb a3285a06ee68273c89bf039e2c68ed2d39e2e82926708e788b872b812308e984 3629086 libtomcat7-java_7.0.56-3+deb8u7_all.deb 159c305eee5bb0b040b481caac712a419aecb23fc5ee0690acfadfa7bea1ec2e 316016 libservlet3.0-java_7.0.56-3+deb8u7_all.deb 8d1d27587e23ca3ccbd312e73a1c5bdb9e9acf4e49b2ae2d429d1d8d612dc103 206334 libservlet3.0-java-doc_7.0.56-3+deb8u7_all.deb 4b095ca4bdf035e10555e8289de496e5262cd6c8e292741195e41d6ee6d97f61 41076 tomcat7-admin_7.0.56-3+deb8u7_all.deb 32ff903ab38b3f723752d1defcb18ae844d5ec0ea9d608ad59c93686890c0a09 199238 tomcat7-examples_7.0.56-3+deb8u7_all.deb eec40ed8652f9e14352ff6277da4a56aec9462b94630acd149cd785cff5d4adf 605872 tomcat7-docs_7.0.56-3+deb8u7_all.deb Files: 06fb54e743e365c6ce4d018c82296850 2758 java optional tomcat7_7.0.56-3+deb8u7.dsc 2cc8822c740223409c3834cc2729b68e 90340 java optional tomcat7_7.0.56-3+deb8u7.debian.tar.xz e30fea0abce868b72ca7989344e62d26 63770 java optional tomcat7-common_7.0.56-3+deb8u7_all.deb 05507ddfa0699a2dfe6b3ffa98c13b3a 52598 java optional tomcat7_7.0.56-3+deb8u7_all.deb 20a5635039b02c0ea52f5677aa401e6a 40080 java optional tomcat7-user_7.0.56-3+deb8u7_all.deb 5ae31f12e8063447e350e181a9227e11 3629086 java optional libtomcat7-java_7.0.56-3+deb8u7_all.deb 1c13e184a38cc5882483101baf15a628 316016 java optional libservlet3.0-java_7.0.56-3+deb8u7_all.deb fb9b0773274bfcdc07139734a1eebb2b 206334 doc optional libservlet3.0-java-doc_7.0.56-3+deb8u7_all.deb 10e7af45ac72df0f6595c8d2b4295107 41076 java optional tomcat7-admin_7.0.56-3+deb8u7_all.deb c6cb7b774c396730d9882e651b6c871e 199238 java optional tomcat7-examples_7.0.56-3+deb8u7_all.deb 9fc21c7c8c8f0e69d3ee4c17f7966c7c 605872 doc optional tomcat7-docs_7.0.56-3+deb8u7_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBAgAGBQJYb2qsAAoJEPUTxBnkudCs2boP/idFHXkGPq/lRsj5eGDQPn9c BL5P2SEpdOxt/UojQgzn5uWaSixMHbaFCgyoeiYFWVEeLMVvdoR9OGUbZ68AlmUs Is3qq5rgrcLjx/IrHLnDpnkI1JJ94Lh8yO528xWZC35bIzCdck7V2In/SuHGd3ns wQddISqz0klPkK1caQ7IpbiEvAQqqH0/Bo7siXjHCzoHreRHycvM3IaEhJH1/wbx tEJunnF4kiTeV2P2n4gf0vysiMoz3ynaYF+SImJKSEqVn05JSd3AmbZoDgth5Wwv 32aw1j4wae8lGJmucMljSOLaPCn7uB3WiyrEYWDZHGghZUWLw7pXXywF9vU/J98a ErvyPvt1653yaUDZwk2tbsly9kmHv2ZxhRjnY/8uFEmwoRTx45Ep+twJNUc7IXyN ap0imZ8VK0s/fJ+53QBKc2Uhin4KsEZ96biHJSCteweRD7KfIB/z81ioZm4gdlug 1QqfBDoJgWwSDsIesUZpYyDNeDsEo7NNLqIoFcvQKPyTgDorhhl+ul/nLvYtgoAy MRYDk3jCFCjQ9f2s13VybtZiCs3iQAGLn6sQiitxDkfMzWPBSL7LvnvY65xJZFEm 7E3v5Pm92idoFp+jdvwjELGG65YEzjA7XchU9Dl1C+Hgirkpg/IJSIgKGAOSLGeN Dl5oDRvcAESNEeh+WZKA =TqqW -----END PGP SIGNATURE-----