Bug#494799: CVE-2008-2938: Directory Traversal Vulnerability

2008-08-12 Thread Christophe Boyanique
Package: tomcat5.5
Version: 5.5.20-2etch3
Severity: grave
Tags: security

Tomcat is affected by a directory traversal vulnerability. The problem
has been fixed in SVN version:

- http://tomcat.apache.org/security-5.html

Available information:
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2938
- http://www.milw0rm.com/exploits/6229

Christophe.



___
pkg-java-maintainers mailing list
pkg-java-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/mailman/listinfo/pkg-java-maintainers


Bug#494799: CVE-2008-2938: Directory Traversal Vulnerability

2008-08-12 Thread Nico Golde
merge 494504 494799
thanks

Hi Christophe,
* Christophe Boyanique [EMAIL PROTECTED] [2008-08-12 12:37]:
 Package: tomcat5.5
 Version: 5.5.20-2etch3
 Severity: grave
 Tags: security
 
 Tomcat is affected by a directory traversal vulnerability. The problem
 has been fixed in SVN version:

Please check the existing BTS entries before submitting new 
bugs. No idea how you missed:
#494504 [G|S|] [tomcat5.5] CVE-2008-1232/CVE-2008-2370: XSS and directory 
traversal

Check out 
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494504

Cheers
Nico
-- 
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.



___
pkg-java-maintainers mailing list
pkg-java-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/mailman/listinfo/pkg-java-maintainers