Bug#612257: Three Tomcat vulnerabilities

2011-02-10 Thread Julien Cristau
On Thu, Feb 10, 2011 at 07:28:33 -0800, tony mancill wrote:

> Hello Moritz,
> 
You don't seem to have sent this to Moritz, only to the bug?

Cheers,
Julien


signature.asc
Description: Digital signature


Bug#612257: Three Tomcat vulnerabilities

2011-02-10 Thread tony mancill
Hello Moritz,

I have uploaded the patched tomcat6 package to unstable and will now build for
squeeze, which I will then upload to my p.d.o page for review.

One question first.  There was one pending update already in SVN for the
Brazilian debconf translation, which I included in the upload to unstable.  Do
you think it's acceptable to allow this to be included in upload for
squeeze-security, or does that bit need to be excluded?  (I'm trying to decide
where to branch in the packaging repo.)

Thank you,
tony

On 02/07/2011 12:00 AM, Moritz Muehlenhoff wrote:
> Package: tomcat6
> Version: Three Tomcat vulnerabilities
> Severity: grave
> Tags: security
> 
> CVE-2011-0534, CVE-2011-0013 and CVE-2010-3718 need to be
> fixed in squeeze-security and unstable:
> 
> http://tomcat.apache.org/security-6.html
> 
> Cheers,




signature.asc
Description: OpenPGP digital signature


Bug#612257: Three Tomcat vulnerabilities

2011-02-07 Thread tony mancill
On 02/07/2011 12:00 AM, Moritz Muehlenhoff wrote:
> Package: tomcat6
> Version: Three Tomcat vulnerabilities
> Severity: grave
> Tags: security
> 
> CVE-2011-0534, CVE-2011-0013 and CVE-2010-3718 need to be
> fixed in squeeze-security and unstable:
> 
> http://tomcat.apache.org/security-6.html

Hello Moritz,

Thank you for the notification and the link.  I'll prepare an upload of
6.0.28-10 for unstable and then a build for squeeze.

Regards,
tony




-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#612257: Three Tomcat vulnerabilities

2011-02-07 Thread Moritz Muehlenhoff
Package: tomcat6
Version: Three Tomcat vulnerabilities
Severity: grave
Tags: security

CVE-2011-0534, CVE-2011-0013 and CVE-2010-3718 need to be
fixed in squeeze-security and unstable:

http://tomcat.apache.org/security-6.html

Cheers,
Moritz

-- System Information:
Debian Release: 5.0.1
Architecture: amd64 (x86_64)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.32-ucs35-amd64
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org