-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 24 Sep 2017 16:35:16 +0200 Source: tomcat7 Binary: tomcat7-common tomcat7 tomcat7-user libtomcat7-java libservlet3.0-java libservlet3.0-java-doc tomcat7-admin tomcat7-examples tomcat7-docs Architecture: source all Version: 7.0.28-4+deb7u15 Distribution: wheezy-security Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: libservlet3.0-java - Servlet 3.0 and JSP 2.2 Java API classes libservlet3.0-java-doc - Servlet 3.0 and JSP 2.2 Java API documentation libtomcat7-java - Servlet and JSP engine -- core libraries tomcat7 - Servlet and JSP engine tomcat7-admin - Servlet and JSP engine -- admin web applications tomcat7-common - Servlet and JSP engine -- common files tomcat7-docs - Servlet and JSP engine -- documentation tomcat7-examples - Servlet and JSP engine -- example web applications tomcat7-user - Servlet and JSP engine -- tools to create user instances Changes: tomcat7 (7.0.28-4+deb7u15) wheezy-security; urgency=high . * Team upload. * Fix CVE-2017-12616. When using a VirtualDirContext it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request. Checksums-Sha1: 8fa7a6071d58b3e8660cfcf15d25540386f711bf 2799 tomcat7_7.0.28-4+deb7u15.dsc 9c6265786b9b2662ab4245ffc532e328be46c3e9 196634 tomcat7_7.0.28-4+deb7u15.debian.tar.gz 665ad97605717957cc4c72f7d309c279c9bcfec3 67028 tomcat7-common_7.0.28-4+deb7u15_all.deb 962ae69acd0001d0539f29a3242a27190ab36163 54100 tomcat7_7.0.28-4+deb7u15_all.deb 5dde894c6ff4c3dca73c7d5620a28d33c65eb1d3 42392 tomcat7-user_7.0.28-4+deb7u15_all.deb 6f6daabb1c0e92a93c33f8d74870cb4d3263ba84 3510866 libtomcat7-java_7.0.28-4+deb7u15_all.deb f22a606301e4ce4f2e1cc4d56eb704054bffcac1 308496 libservlet3.0-java_7.0.28-4+deb7u15_all.deb 8caa3fde9e7f690797fd54bab16bb18c428dd0d4 322726 libservlet3.0-java-doc_7.0.28-4+deb7u15_all.deb 4cff4e186d752e7895da9969f175aa6448d1fdee 54966 tomcat7-admin_7.0.28-4+deb7u15_all.deb 0030c82785da7137805d3950adff1e0531029774 208660 tomcat7-examples_7.0.28-4+deb7u15_all.deb a65cd8636f9908f8bd896eec5788e71d11e983fc 649598 tomcat7-docs_7.0.28-4+deb7u15_all.deb Checksums-Sha256: 9176a0330311e4cdfd0926141631a450f37be3889c2d03fd84e50c7b5dccb013 2799 tomcat7_7.0.28-4+deb7u15.dsc 87bbbd288da1fe3e6c6ef3d7d599939e704382bb9e2f5188580cc1211babccd6 196634 tomcat7_7.0.28-4+deb7u15.debian.tar.gz 4f527b6d238be176d653e10d81b430d9c43bf32dc511ed9b2781e4c13707b3b5 67028 tomcat7-common_7.0.28-4+deb7u15_all.deb d25fb0f136196a3d8939bf906154587f71beb268beccc5c7049000af682fdbda 54100 tomcat7_7.0.28-4+deb7u15_all.deb 55860f70eb128454e9fca8a9d96381f72f11e4ea58ae76ed3ad956e0fcbbf7e6 42392 tomcat7-user_7.0.28-4+deb7u15_all.deb 980587757f0879534ce2983706436c7397c5927e08ce13ab6095043a380aaced 3510866 libtomcat7-java_7.0.28-4+deb7u15_all.deb 59352e4d1857afa4962619d636aabd21bb4e10b06849fb17c54810a81720fea7 308496 libservlet3.0-java_7.0.28-4+deb7u15_all.deb ec01f4dcaa4d43764bb1d0307c131056eceab62e07d83887cc84fc44357ff8d7 322726 libservlet3.0-java-doc_7.0.28-4+deb7u15_all.deb 852740cff67e3a5e20bbbf1c8b7a7f4462e55af95a66447366f92b09ad0aad1f 54966 tomcat7-admin_7.0.28-4+deb7u15_all.deb 6e24f74cf5561872642af3cd71afb3da895d0acf88fdceb01a6aefbefae1490f 208660 tomcat7-examples_7.0.28-4+deb7u15_all.deb b40c44dd4066d584be05fa7d74fd93863426402d27319bb5fcb7228f15c071c8 649598 tomcat7-docs_7.0.28-4+deb7u15_all.deb Files: 33ffa46450185b598f3c7ada4c9be0e2 2799 java optional tomcat7_7.0.28-4+deb7u15.dsc f1461c79bc544eb168a70fd7a4555953 196634 java optional tomcat7_7.0.28-4+deb7u15.debian.tar.gz ade74cdcc1f8320c20be469a646f588f 67028 java optional tomcat7-common_7.0.28-4+deb7u15_all.deb 9399a031316a854294c2039249cfd7ee 54100 java optional tomcat7_7.0.28-4+deb7u15_all.deb afa0de9ae84d884aee5565b75b565e3d 42392 java optional tomcat7-user_7.0.28-4+deb7u15_all.deb cf27f5744b36e3cc263cae32a4a37971 3510866 java optional libtomcat7-java_7.0.28-4+deb7u15_all.deb 253d29e61b1fd9b3573646bc55f53455 308496 java optional libservlet3.0-java_7.0.28-4+deb7u15_all.deb c160bed062cb9da531a6e684afad4cb1 322726 doc optional libservlet3.0-java-doc_7.0.28-4+deb7u15_all.deb da834a7f2bcff4920d026673d83a5a66 54966 java optional tomcat7-admin_7.0.28-4+deb7u15_all.deb 73bf02b466b6fbd8d2353c053caa46ee 208660 java optional tomcat7-examples_7.0.28-4+deb7u15_all.deb 9b079161ca5fd89191d40f1ec25b6008 649598 doc optional tomcat7-docs_7.0.28-4+deb7u15_all.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlnH23xfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1Hk1vIP/RnrX5s+DTvevyqwBeDF9Nb1MH3R6llYi8LQ OFbpArDp7J2y1Y39Yz6UmdNTZPT0UUVzdPORDLLxtcxvmsvLqCqdjeGbRhd8hUZB Rh5Qp2e35Pv0PJ6/qpuurdhTqVX74pTAnAE/KokZ9n4izJraZyKbqovV9Ab8wjyH jfJr67zccz23oenwWjBmMABT9ERZXMqQ3VsEmXY1A/Z7w62cjnxzDq7Zv5ld0hOk h2zZU1Q6u8qwzcQkeqsdYJL79Jt0aKCFCQYket12vDOEUZ2I8gaE/rdZGgw3uEZT jIiEU/ToQbflsbsdtiCXwM9axO75eNSabi3slqXm0iQ27UJV4MVamPcXlqDkNIqd zLB07A6FuYGoQdyu/eoOQlACoRMYzv+KxGyEnasQ8JCN1Lza2xuy4bsjGnvs/o5W rzHfmO0DNmGGAZG3yi+3W4JgZouicXKFbjK1R8yggshPRmk4x1/XugwAycg3GOhW UuYxTHizLxEVoVQ9kkV0VgniZPloTuLNLDvuAp3dlz49zZrvSiVZ69ueqFbuPSRo SjtxddCSvPHEc4q78asmuZCn1CAKMATnqBMbQifJ1kCW5264f+SJ4jVZuc5lF+O2 KUDaSF7xqUKE3bEDWlwHM+1Gs6ivrYYVi4AGZ4/HGAuwIodqWR2mDwwKdaoPFWwW qi8sZyY3 =6IgZ -----END PGP SIGNATURE-----