-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 30 Jul 2018 02:31:58 +0200 Source: tomcat7 Binary: tomcat7-common tomcat7 tomcat7-user libtomcat7-java libservlet3.0-java libservlet3.0-java-doc tomcat7-admin tomcat7-examples tomcat7-docs Architecture: source all Version: 7.0.56-3+really7.0.90-1 Distribution: jessie-security Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: libservlet3.0-java - Servlet 3.0 and JSP 2.2 Java API classes libservlet3.0-java-doc - Servlet 3.0 and JSP 2.2 Java API documentation libtomcat7-java - Servlet and JSP engine -- core libraries tomcat7 - Servlet and JSP engine tomcat7-admin - Servlet and JSP engine -- admin web applications tomcat7-common - Servlet and JSP engine -- common files tomcat7-docs - Servlet and JSP engine -- documentation tomcat7-examples - Servlet and JSP engine -- example web applications tomcat7-user - Servlet and JSP engine -- tools to create user instances Changes: tomcat7 (7.0.56-3+really7.0.90-1) jessie-security; urgency=high . * Non-maintainer upload by the LTS team. * New upstream version 7.0.90. Fix CVE-2018-8034: The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. * Rebase 0017-use-jdbc-pool-default.patch. Checksums-Sha1: e669b9126a090a07cfe311ee1b9b6b447ee13aaa 3026 tomcat7_7.0.56-3+really7.0.90-1.dsc c216f4498b9830d183d528583ae40b3b5870b8b0 3266996 tomcat7_7.0.56-3+really7.0.90.orig.tar.xz da93c417df3d2f8a949ed90390a71ddcc0ea77b9 52536 tomcat7_7.0.56-3+really7.0.90-1.debian.tar.xz eae7ad7cefc5087e169de595a7b3e402b21b300d 295064 tomcat7-common_7.0.56-3+really7.0.90-1_all.deb b36b2efe80fd16f5ef6928c6aecad9a513966afc 55128 tomcat7_7.0.56-3+really7.0.90-1_all.deb dde7f3dba6d004328e39d2ee4894716636ff39de 42526 tomcat7-user_7.0.56-3+really7.0.90-1_all.deb 09cc46fdc87b3075a8250751d0a60460a5871275 3811082 libtomcat7-java_7.0.56-3+really7.0.90-1_all.deb 54d0186c72ad10c6ff9f5d842ab3df7f6c0c43f1 317764 libservlet3.0-java_7.0.56-3+really7.0.90-1_all.deb 193208e98e00f96b06a17a2adf5aa03a1a8a4707 209172 libservlet3.0-java-doc_7.0.56-3+really7.0.90-1_all.deb 471268776b480efcf940f03fb5d1b204dff4ba79 38950 tomcat7-admin_7.0.56-3+really7.0.90-1_all.deb 2097fd46545d79503d257e7a7ba2536395b1fa60 201972 tomcat7-examples_7.0.56-3+really7.0.90-1_all.deb 2e3e8cf4a980eedb72610b8c7b69e1eda1fb84ae 684744 tomcat7-docs_7.0.56-3+really7.0.90-1_all.deb Checksums-Sha256: 94c864c1b206c2f1fcd22f20e4797c833ad96cb0d2dc9fe3fe5b40f72e1406e8 3026 tomcat7_7.0.56-3+really7.0.90-1.dsc 0b04c8311506a61de9744faab1b515ec6b26a5d7764092d970d13f2cc4e442a4 3266996 tomcat7_7.0.56-3+really7.0.90.orig.tar.xz 5165bc58e76228d6339535a782b0b5c79adf4b7d5bf42ffd590d8196b5fb3c01 52536 tomcat7_7.0.56-3+really7.0.90-1.debian.tar.xz 8f39c4e76458a605cb4a1c474df91867a349e31875fe0bb5c5f445f1e1aed320 295064 tomcat7-common_7.0.56-3+really7.0.90-1_all.deb 1a0b5199a7b12cdee1949f01a767fad50299ebdc0d527663ca14609b3cde1106 55128 tomcat7_7.0.56-3+really7.0.90-1_all.deb 9db5b59a9d1e7d12c517f05cb46ddf272817618f51eedfe8aafd63dcf22668f0 42526 tomcat7-user_7.0.56-3+really7.0.90-1_all.deb ea833e1a3ade0621fc54e61b6852669ad3a3a521bcfff1cd3b9febf5fec0932d 3811082 libtomcat7-java_7.0.56-3+really7.0.90-1_all.deb 368629d9eaba94e54bcf4ce681fbd9bfa6fd3826aa1f1acc084f9efaa86521b8 317764 libservlet3.0-java_7.0.56-3+really7.0.90-1_all.deb 1432c3415001b529093366867d3e963c67dc8d7080d43d79c8aa410832a94947 209172 libservlet3.0-java-doc_7.0.56-3+really7.0.90-1_all.deb ebdb0d2c85e35dc884b77b20cd0530098e4354e59d81881500c976b3383035df 38950 tomcat7-admin_7.0.56-3+really7.0.90-1_all.deb 19b2f9600c5a06c172ed2952eacdecfa56e1f5aaea5febf3b9eadbedbf217687 201972 tomcat7-examples_7.0.56-3+really7.0.90-1_all.deb 9017ffb665bd912d6eb03daebda8797d8ec7ff3412e08424c708ec89eb5bd2b9 684744 tomcat7-docs_7.0.56-3+really7.0.90-1_all.deb Files: f22c88e06149eff339354cc0b6747e03 3026 java optional tomcat7_7.0.56-3+really7.0.90-1.dsc 0948383549df797e12093ff955084288 3266996 java optional tomcat7_7.0.56-3+really7.0.90.orig.tar.xz 4aad215e33876b0b7485f7bdb5193f2f 52536 java optional tomcat7_7.0.56-3+really7.0.90-1.debian.tar.xz edc2a8e83bf9ce8df89c73164363bafb 295064 java optional tomcat7-common_7.0.56-3+really7.0.90-1_all.deb 2aa699556c1a817c5fb534ca7b3683d6 55128 java optional tomcat7_7.0.56-3+really7.0.90-1_all.deb f14a487a65b0b8921cda6b7a72e597e4 42526 java optional tomcat7-user_7.0.56-3+really7.0.90-1_all.deb 1a013014a0c616c2f32af5d2d3c21a9f 3811082 java optional libtomcat7-java_7.0.56-3+really7.0.90-1_all.deb 04f3bbc92eedb1f33e6369dd34e5893a 317764 java optional libservlet3.0-java_7.0.56-3+really7.0.90-1_all.deb bfbf4f1924b99aaccffc50323d84adfa 209172 doc optional libservlet3.0-java-doc_7.0.56-3+really7.0.90-1_all.deb 8a7d2ab853f75e574261fc3e8deee7b6 38950 java optional tomcat7-admin_7.0.56-3+really7.0.90-1_all.deb 71f3e0515ba9beb53e802984c860f5de 201972 java optional tomcat7-examples_7.0.56-3+really7.0.90-1_all.deb 26a9faeb8645037dd685159cda233478 684744 doc optional tomcat7-docs_7.0.56-3+really7.0.90-1_all.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlteZrtfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkLmcQAIP57/Hd0ZjEbBjy+jn4zJQCvVUtHv6d+ohf O8iZKpoTyohz4jfx2f1YSGlg3M/pfLjqV7mtdZ/IqFxdhHxfQM+iX5WnTRIqp72H xbcoGKUrbeU5gAaJGSNe0ADYR3XBlOGJ6Nm3QbGnWKjPVnWSOK95nJeepZ3YpJoS jkMbvKi68O4nrJkxTARCmstg53bVox6UaB273PMB9rky6g1OaxjDTY1oZreGGPUM 2nfJUR55VzC0zHrHksEWFP293vi11x80PdGr5bCvD4zoTYyS/bWU1X856ibE0g+w YX9CXbztYQ3usfXmNGDaYjubhhG9tY/sftWo0BM06eKWQ5QO3Gl3YoEVRfC7seTA kRklboSMFH+LA1F4ENdk/FkwaNv8tJl+dNxgW/PCpthcMdWO3flb1jXHu5QH6Be/ IOooe2hg63zAny8rs/6ZI/20+3kOYqxyyMdPlRpXwxPahaoxIXetm6YCW6Z5jRHH 9E1VNle73JGYuf+MdVtQATfzk0srmgh9HM9SB3BIbGFk8cDp8WVcSQPrrGHjiUBH rYOVjnfcBp2Ygr6sjcw/78jHTT9XmS/B3CGuZFDumSv9LbyJdbrH2Ll1y2I3DVSK 2rob0PY+yfNANnSQxoNznW0DWynvPw/2spFbpOvcIi7qFpMbmYuFOsAa21gQeyow 5g+cPpYS =JOym -----END PGP SIGNATURE-----