Bug#849949: version: tomcat7 (7.0.28-4+deb7u8)

2017-01-04 Thread Markus Koschany
On 03.01.2017 01:20, Markus Koschany wrote: [...] > @Karsten > > I have uploaded some new binary packages of Tomcat7 to > > https://people.debian.org/~apo/wheezy-lts/tomcat7/ > > Could you test them on your system and report back if it works for you? > There is also a tomcat7.debdiff which you

Bug#849949: version: tomcat7 (7.0.28-4+deb7u8)

2017-01-02 Thread Markus Koschany
Control: tags -1 confirmed On 02.01.2017 18:00, Emmanuel Bourg wrote: > Hi Karten, > > Thank you for the report. > > It looks like the patch for CVE-2016-6816 applied in 7.0.28-4+deb7u7 is > incomplete. The patch removes the AstAttribute class but > SecurityClassLoad still attempts to load it

Bug#849949: version: tomcat7 (7.0.28-4+deb7u8)

2017-01-02 Thread Emmanuel Bourg
Hi Karten, Thank you for the report. It looks like the patch for CVE-2016-6816 applied in 7.0.28-4+deb7u7 is incomplete. The patch removes the AstAttribute class but SecurityClassLoad still attempts to load it (along with other classes in the same package, also removed). This issue is specific

Bug#849949: version: tomcat7 (7.0.28-4+deb7u8)

2017-01-02 Thread Schöke
Sorry, the version of issue Package is tomcat7 (7.0.28-4+deb7u8) I must install the previous version... Landesvermessung und Geobasisinformation Brandenburg Geokompetenzzentrum Dezernat 13 Technologische Erneuerung Herr Karsten Schöke Postanschrift: Heinrich-Mann-Allee 103, 14473 Potsdam