This bug was fixed in the package tomcat7 - 7.0.30-0ubuntu1.2 --------------- tomcat7 (7.0.30-0ubuntu1.2) quantal-security; urgency=low
* SECURITY UPDATE: FORM authentication request injection - debian/patches/CVE-2013-2067.patch: properly change session ID in java/org/apache/catalina/authenticator/FormAuthenticator.java. - CVE-2013-2067 * SECURITY UPDATE: information leak via AsyncListeners and RuntimeExceptions (LP: #1178645) - debian/patches/CVE-2013-2071.patch: catch RuntimeExceptions in java/org/apache/catalina/core/AsyncContextImpl.java, added tests to test/org/apache/catalina/core/TestAsyncContextImpl.java. - CVE-2013-2071 * Fix FTBFS due to expired test certificates: - d/keystores/*.jks: Newer keystores from upstream 7.0.39. - d/rules: Install newer keystores for testing, tidy up after use. - d/p/0018-update-test-certificates.patch: Cherry picked fixes from upstream VCS to update text based certificates. -- Marc Deslauriers <marc.deslauri...@ubuntu.com> Thu, 23 May 2013 09:04:36 -0400 ** Changed in: tomcat7 (Ubuntu Quantal) Status: Confirmed => Fix Released ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2013-2067 ** Changed in: tomcat7 (Ubuntu Raring) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to tomcat7 in Ubuntu. https://bugs.launchpad.net/bugs/1178645 Title: tomcat7 needs update to 7.0.40 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/tomcat7/+bug/1178645/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs