user release.debian....@packages.debian.org
usertag 608286 squeeze-can-defer
tag 608286 squeeze-ignore
kthxbye

On Wed, Dec 29, 2010 at 18:29:40 +0100, Giuseppe Iuculano wrote:

> Package: tomcat6
> Severity: serious
> Tags: security
> 
> Hi,
> the following CVE (Common Vulnerabilities & Exposures) id was
> published for tomcat6.
> 
> CVE-2010-4312[0]:
> | The default configuration of Apache Tomcat 6.x does not include the
> | HTTPOnly flag in a Set-Cookie header, which makes it easier for remote
> | attackers to hijack a session via script access to a cookie.
> 
> If you fix the vulnerability please also make sure to include the
> CVE id in your changelog entry.
> 
> For further information see:
> 
> [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4312
>     http://security-tracker.debian.org/tracker/CVE-2010-4312
> 
This can be fixed through squeeze-security if it's not ready for
squeeze, so tagging as -can-defer.

Cheers,
Julien

Attachment: signature.asc
Description: Digital signature

__
This is the maintainer address of Debian's Java team
<http://lists.alioth.debian.org/mailman/listinfo/pkg-java-maintainers>. Please 
use
debian-j...@lists.debian.org for discussions and questions.

Reply via email to