• [SECURITY] [DSA 3614-1] tomcat7 security update

    From Salvatore Bonaccorso@1:229/2 to All on Sat Jul 2 15:00:01 2016
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3614-1 [email protected] https://www.debian.org/security/ Salvatore Bonaccorso
    July 02, 2016 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : tomcat7
    CVE ID : CVE-2016-3092

    The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it
    easy to add robust, high-performance, file upload capability to servlets
    and web applications. A remote attacker can take advantage of this flaw
    by sending file upload requests that cause the HTTP server using the
    Apache Commons Fileupload library to become unresponsive, preventing the
    server from servicing other requests.

    Apache Tomcat uses a package renamed copy of Apache Commons FileUpload
    to implement the file upload requirements of the Servlet specification
    and is therefore also vulnerable to the denial of service vulnerability.

    For the stable distribution (jessie), this problem has been fixed in
    version 7.0.56-3+deb8u3.

    For the testing distribution (stretch), this problem has been fixed
    in version 7.0.70-1.

    For the unstable distribution (sid), this problem has been fixed in
    version 7.0.70-1.

    We recommend that you upgrade your tomcat7 packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQIcBAEBCgAGBQJXd7YhAAoJEAVMuPMTQ89Emg0P/2K7qVBmKMDG93HhWe2e5QXk I748PwHm7uHV5qrIYGS8n1LDhqNxOyMaGVJdHzJAvuOJYOVsq2RXLXAhNSNZLPgr mrOCB6i6u1ogY9ztsQi5zprhl6v0AINpQA1pP30COmiS/QlUUbGV09Z952Gg/d25 JDEpvkDmiknAKySP8Jm3GjqhYnJdyOnkRpT/PyJCfepBFk2ToR0HHOPw7kSxkCFV SM8E0ljjrZZVKQ5SRD18egi5VjnV7R/pm+MuejfdtdA+eA/UsrUeQH0kVWNN8LUP Hfry2Dz11tAi8WfdP9nc4cPm9m1XLG4S64J3ZwwUNzyuxYXpkyzKIViQDuO4WHMR vKZpUjYuRcSGqySdhN2HdYxgZET3avO20tN39+iH2ASuv5LDZJ6tOQXX713+Xox1 988nMEDkxIWbgPgfIhEhPIRoW8efEAczHoY80XxjAPJF9PokCqN5OjFBQPS60D3z zycu8+Hrxlx3C8emkVElDaFeyTmWYrMxJ/yEBEN+m0dhMdbzcwlXTAtLgrXkQUga Ly8RmMpougmN0Kx0CqCwYKyxzn7peSi2LP90gfHu5etks3rtN122c2R69Ma1DbXh mEMj0K9R2qjKFJeZ9fIU7Gxx9+Wo0dJnlEMc3jL2Ne36HBrcP3fQuKnQxw2lWbaP yL3atzZ13OmvyxAJltuN
    =RBqU
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)