DSA-3843-1 tomcat8 -- security update

Related Vulnerabilities: CVE-2017-5647   CVE-2017-5648  

Two vulnerabilities were discovered in tomcat8, a servlet and JSP engine. CVE-2017-5647 Pipelined requests were processed incorrectly, which could result in some responses appearing to be sent for the wrong request. CVE-2017-5648 Some application listeners calls were issued against the wrong objects, allowing untrusted applications running under a SecurityManager to bypass that protection mechanism and access or modify information associated with other web applications. For the stable distribution (jessie), these problems have been fixed in version 8.0.14-1+deb8u9. For the upcoming stable (stretch) and unstable (sid) distributions, these problems have been fixed in version 8.5.11-2. We recommend that you upgrade your tomcat8 packages.

Debian Security Advisory

DSA-3843-1 tomcat8 -- security update

Date Reported:
03 May 2017
Affected Packages:
tomcat8
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 860068, Bug 860069.
In Mitre's CVE dictionary: CVE-2017-5647, CVE-2017-5648.
More information:

Two vulnerabilities were discovered in tomcat8, a servlet and JSP engine.

  • CVE-2017-5647

    Pipelined requests were processed incorrectly, which could result in some responses appearing to be sent for the wrong request.

  • CVE-2017-5648

    Some application listeners calls were issued against the wrong objects, allowing untrusted applications running under a SecurityManager to bypass that protection mechanism and access or modify information associated with other web applications.

For the stable distribution (jessie), these problems have been fixed in version 8.0.14-1+deb8u9.

For the upcoming stable (stretch) and unstable (sid) distributions, these problems have been fixed in version 8.5.11-2.

We recommend that you upgrade your tomcat8 packages.