tomcat6: CVE-2012-2733 CVE-2012-3439

Related Vulnerabilities: CVE-2012-2733   CVE-2012-3439  

Debian Bug report logs - #692439
tomcat6: CVE-2012-2733 CVE-2012-3439

version graph

Reported by: Moritz Muehlenhoff <jmm@inutil.org>

Date: Tue, 6 Nov 2012 10:42:01 UTC

Severity: grave

Tags: security

Fixed in version 6.0.35-5+nmu1

Done: Michael Gilbert <mgilbert@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>:
Bug#692439; Package tomcat6. (Tue, 06 Nov 2012 10:42:04 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@inutil.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>. (Tue, 06 Nov 2012 10:42:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@inutil.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: tomcat6: CVE-2012-2733 CVE-2012-3439
Date: Tue, 06 Nov 2012 11:37:21 +0100
Package: tomcat6
Severity: grave
Tags: security
Justification: user security hole

Please see http://tomcat.apache.org/security-6.html

Since Wheezy is frozen, please apply isolated security fixes and do not update
to a new upstream release.

BTW, is it really necessary to have both tomcat6 and tomcat7 in Wheezy? Shouldn't
tomcat6 be dropped in favour of tomcat7?

Cheers,
        Moritz



Reply sent to Michael Gilbert <mgilbert@debian.org>:
You have taken responsibility. (Sun, 18 Nov 2012 01:51:03 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@inutil.org>:
Bug acknowledged by developer. (Sun, 18 Nov 2012 01:51:04 GMT) (full text, mbox, link).


Message #10 received at 692439-close@bugs.debian.org (full text, mbox, reply):

From: Michael Gilbert <mgilbert@debian.org>
To: 692439-close@bugs.debian.org
Subject: re: tomcat6: CVE-2012-2733 CVE-2012-3439
Date: Sat, 17 Nov 2012 20:48:41 -0500
[Message part 1 (text/plain, inline)]
version: 6.0.35+nmu1

Hi, I've uploaded an nmu fixing this issue.  Please see attached
patch.  Note I incorrectly entered the tomcat7 bug in the changelog,
which should be corrected in the next upload.

Best wishes,
Mike
[tomcat6.patch (application/octet-stream, attachment)]

Marked as found in versions 6.035-5+nmu1 and reopened. Request was from Michael Gilbert <mgilbert@debian.org> to control@bugs.debian.org. (Sun, 18 Nov 2012 16:36:06 GMT) (full text, mbox, link).


No longer marked as fixed in versions 6.0.35+nmu1. Request was from Michael Gilbert <mgilbert@debian.org> to control@bugs.debian.org. (Sun, 18 Nov 2012 16:39:11 GMT) (full text, mbox, link).


Marked as fixed in versions 6.035-5+nmu1. Request was from Michael Gilbert <mgilbert@debian.org> to control@bugs.debian.org. (Sun, 18 Nov 2012 16:39:11 GMT) (full text, mbox, link).


No longer marked as found in versions 6.035-5+nmu1. Request was from Michael Gilbert <mgilbert@debian.org> to control@bugs.debian.org. (Sun, 18 Nov 2012 16:45:07 GMT) (full text, mbox, link).


No longer marked as fixed in versions 6.035-5+nmu1. Request was from Michael Gilbert <mgilbert@debian.org> to control@bugs.debian.org. (Sun, 18 Nov 2012 16:45:08 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>:
Bug#692439; Package tomcat6. (Sun, 18 Nov 2012 16:51:05 GMT) (full text, mbox, link).


Acknowledgement sent to Michael Gilbert <mgilbert@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>. (Sun, 18 Nov 2012 16:51:05 GMT) (full text, mbox, link).


Message #25 received at 692439@bugs.debian.org (full text, mbox, reply):

From: Michael Gilbert <mgilbert@debian.org>
To: 692439@bugs.debian.org
Subject: closing
Date: Sun, 18 Nov 2012 11:48:46 -0500
version: 6.0.35-5+nmu1



Reply sent to Michael Gilbert <mgilbert@debian.org>:
You have taken responsibility. (Sun, 18 Nov 2012 16:57:09 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@inutil.org>:
Bug acknowledged by developer. (Sun, 18 Nov 2012 16:57:09 GMT) (full text, mbox, link).


Message #30 received at 692439-close@bugs.debian.org (full text, mbox, reply):

From: Michael Gilbert <mgilbert@debian.org>
To: 692439-close@bugs.debian.org
Subject: Re: closing
Date: Sun, 18 Nov 2012 11:52:40 -0500
version: 6.0.35-5+nmu1



Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 24 Dec 2012 07:27:27 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 14:20:36 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.