CVE-2011-2204

Related Vulnerabilities: CVE-2011-2204  

Debian Bug report logs - #632882
CVE-2011-2204

version graph

Reported by: Moritz Muehlenhoff <jmm@debian.org>

Date: Wed, 6 Jul 2011 18:00:04 UTC

Severity: grave

Tags: security

Fixed in versions tomcat6/6.0.32-5, tomcat7/7.0.16-3

Done: tony mancill <tmancill@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, jmw@debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>:
Bug#632882; Package tomcat6. (Wed, 06 Jul 2011 18:00:07 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, jmw@debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>. (Wed, 06 Jul 2011 18:00:08 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2011-2204
Date: Wed, 06 Jul 2011 19:58:32 +0200
Package: tomcat6
Severity: grave
Tags: security

(Also applies to Tomcat 5.5 and Tomcat 6)

Please see
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2204

This doesn't warrant a DSA, but could be fixed through a point
update.

Cheers,
        Moritz

-- System Information:
Debian Release: wheezy/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.39-2-amd64 (SMP w/2 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash




Information forwarded to debian-bugs-dist@lists.debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>:
Bug#632882; Package tomcat6. (Thu, 07 Jul 2011 04:51:03 GMT) (full text, mbox, link).


Acknowledgement sent to tony mancill <tmancill@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>. (Thu, 07 Jul 2011 04:51:03 GMT) (full text, mbox, link).


Message #10 received at 632882@bugs.debian.org (full text, mbox, reply):

From: tony mancill <tmancill@debian.org>
To: 632882@bugs.debian.org
Cc: Moritz Muehlenhoff <jmm@debian.org>
Subject: Re: Bug#632882: CVE-2011-2204
Date: Wed, 06 Jul 2011 21:49:17 -0700
[Message part 1 (text/plain, inline)]
Hello Moritz,

Thank you for filing the bug.  I've uploaded an updated tomcat6 package
for unstable and will get the patch applied for the next tomcat7 upload
soon.  I'll also look into an upload of 6.0.28 for stable proposed updates.

Cheers,
tony

On 07/06/2011 10:58 AM, Moritz Muehlenhoff wrote:
> Package: tomcat6
> Severity: grave
> Tags: security
> 
> (Also applies to Tomcat 5.5 and Tomcat 6)
> 
> Please see
> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2204
> 
> This doesn't warrant a DSA, but could be fixed through a point
> update.
> 
> Cheers,
>         Moritz

[signature.asc (application/pgp-signature, attachment)]

Reply sent to tony mancill <tmancill@debian.org>:
You have taken responsibility. (Thu, 07 Jul 2011 04:51:10 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@debian.org>:
Bug acknowledged by developer. (Thu, 07 Jul 2011 04:51:10 GMT) (full text, mbox, link).


Message #15 received at 632882-close@bugs.debian.org (full text, mbox, reply):

From: tony mancill <tmancill@debian.org>
To: 632882-close@bugs.debian.org
Subject: Bug#632882: fixed in tomcat6 6.0.32-5
Date: Thu, 07 Jul 2011 04:47:27 +0000
Source: tomcat6
Source-Version: 6.0.32-5

We believe that the bug you reported is fixed in the latest version of
tomcat6, which is due to be installed in the Debian FTP archive:

libservlet2.5-java-doc_6.0.32-5_all.deb
  to main/t/tomcat6/libservlet2.5-java-doc_6.0.32-5_all.deb
libservlet2.5-java_6.0.32-5_all.deb
  to main/t/tomcat6/libservlet2.5-java_6.0.32-5_all.deb
libtomcat6-java_6.0.32-5_all.deb
  to main/t/tomcat6/libtomcat6-java_6.0.32-5_all.deb
tomcat6-admin_6.0.32-5_all.deb
  to main/t/tomcat6/tomcat6-admin_6.0.32-5_all.deb
tomcat6-common_6.0.32-5_all.deb
  to main/t/tomcat6/tomcat6-common_6.0.32-5_all.deb
tomcat6-docs_6.0.32-5_all.deb
  to main/t/tomcat6/tomcat6-docs_6.0.32-5_all.deb
tomcat6-examples_6.0.32-5_all.deb
  to main/t/tomcat6/tomcat6-examples_6.0.32-5_all.deb
tomcat6-extras_6.0.32-5_all.deb
  to main/t/tomcat6/tomcat6-extras_6.0.32-5_all.deb
tomcat6-user_6.0.32-5_all.deb
  to main/t/tomcat6/tomcat6-user_6.0.32-5_all.deb
tomcat6_6.0.32-5.debian.tar.gz
  to main/t/tomcat6/tomcat6_6.0.32-5.debian.tar.gz
tomcat6_6.0.32-5.dsc
  to main/t/tomcat6/tomcat6_6.0.32-5.dsc
tomcat6_6.0.32-5_all.deb
  to main/t/tomcat6/tomcat6_6.0.32-5_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 632882@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
tony mancill <tmancill@debian.org> (supplier of updated tomcat6 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Wed, 06 Jul 2011 21:23:58 -0700
Source: tomcat6
Binary: tomcat6-common tomcat6 tomcat6-user libtomcat6-java libservlet2.5-java libservlet2.5-java-doc tomcat6-admin tomcat6-examples tomcat6-docs tomcat6-extras
Architecture: source all
Version: 6.0.32-5
Distribution: unstable
Urgency: low
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: tony mancill <tmancill@debian.org>
Description: 
 libservlet2.5-java - Servlet 2.5 and JSP 2.1 Java API classes
 libservlet2.5-java-doc - Servlet 2.5 and JSP 2.1 Java API documentation
 libtomcat6-java - Servlet and JSP engine -- core libraries
 tomcat6    - Servlet and JSP engine
 tomcat6-admin - Servlet and JSP engine -- admin web applications
 tomcat6-common - Servlet and JSP engine -- common files
 tomcat6-docs - Servlet and JSP engine -- documentation
 tomcat6-examples - Servlet and JSP engine -- example web applications
 tomcat6-extras - Servlet and JSP engine -- additional components
 tomcat6-user - Servlet and JSP engine -- tools to create user instances
Closes: 630073 631919 632882
Changes: 
 tomcat6 (6.0.32-5) unstable; urgency=low
 .
   * Team upload.
   * Add Catalan debconf translation ca.po (Closes: #630073).
   * Correct Suggests for libtcnative-1 (tomcat-native) (Closes: #631919)
   * Add patch for CVE-2011-2204 (Closes: #632882)
Checksums-Sha1: 
 84b8e3dfb0486b83682b472f78931934aa300836 2271 tomcat6_6.0.32-5.dsc
 25209bf96d21acb16ac98afaab170ff2d1cdf1c9 43416 tomcat6_6.0.32-5.debian.tar.gz
 32033a8cfcfc071c5f82f4d07b67ded2389835bf 48832 tomcat6-common_6.0.32-5_all.deb
 a0f4f08f51378efb4846bbcfba703d03527c3218 37890 tomcat6_6.0.32-5_all.deb
 8feb90a81f2fcad324861b7dabdaa92d584318f2 29550 tomcat6-user_6.0.32-5_all.deb
 9bf442f7d8a36187542543defdbff1178dc00c09 3066114 libtomcat6-java_6.0.32-5_all.deb
 d5358e11032f1e2e1aba08a6158d579aaada7a78 194232 libservlet2.5-java_6.0.32-5_all.deb
 07d0fb203e83a7ff788c8a4318e287a6120de260 256934 libservlet2.5-java-doc_6.0.32-5_all.deb
 d9fccb01a29ebb76c7c12a56a5d7e4cea5d485f3 48252 tomcat6-admin_6.0.32-5_all.deb
 e6e191cfe0de7d931cc4ed6a39c47bf6bac6e1ff 163204 tomcat6-examples_6.0.32-5_all.deb
 c030742e0c409cff8624400a49f0f4f9fdee08e3 546138 tomcat6-docs_6.0.32-5_all.deb
 8c94b0ff51d3db3ef0fd974f60ccb94b0b56c206 12166 tomcat6-extras_6.0.32-5_all.deb
Checksums-Sha256: 
 d5585e1c508a60662d04580c3bc5bf4b6ced1bcc98a0b52473e9220a23036918 2271 tomcat6_6.0.32-5.dsc
 790e7bbb2f333e52f3721d742465cb0aa6cb2e38dbc2724a0e39a6b84a8cafcc 43416 tomcat6_6.0.32-5.debian.tar.gz
 2f8247010a9ef9ac5a244c48052fcd48666db60d4cb1203378c3a28ec6f64528 48832 tomcat6-common_6.0.32-5_all.deb
 59b5783ab8fdd107262481c9ba488b89ea872cf03b0304355c51c7a374253a19 37890 tomcat6_6.0.32-5_all.deb
 f0e0ca563488eb6ad988cf2d2861acd8fcfdd2907760a5a6ed94a14103d4ecba 29550 tomcat6-user_6.0.32-5_all.deb
 f5e512870ba843a2702f1557ad8eb84127bb930680f26ccb8135e5ea8c3d5c98 3066114 libtomcat6-java_6.0.32-5_all.deb
 f82e9fe81c32adb5a9f652f866616a7f8137b1c0460072445daf48566594d3ca 194232 libservlet2.5-java_6.0.32-5_all.deb
 61ada278954274b72a045c49f17917e265d9a5f8fe03638fdb133f0111f56ce4 256934 libservlet2.5-java-doc_6.0.32-5_all.deb
 3d797201af0df5edd4a7127c4ffe7f331f1721f3c4c89a485a81326720b4adf4 48252 tomcat6-admin_6.0.32-5_all.deb
 a45603caebf14affc6804af989a6b97cc524684e4e6d32386f56c755c9a3501d 163204 tomcat6-examples_6.0.32-5_all.deb
 071549460f1b94ecef4a0184b5459884dd32557d6fad5c8f79b713e4e2736ebc 546138 tomcat6-docs_6.0.32-5_all.deb
 c22b299041050c0c65d22284925285dc82fc50d630f45c2cfdc0d47c0e78258f 12166 tomcat6-extras_6.0.32-5_all.deb
Files: 
 9b2cb2103bb56076af30dc79398bc5f5 2271 java optional tomcat6_6.0.32-5.dsc
 eeccfb925d62b25b6a39e458aece4ad7 43416 java optional tomcat6_6.0.32-5.debian.tar.gz
 619c0d2726fd5c3e107ffbd98fb16963 48832 java optional tomcat6-common_6.0.32-5_all.deb
 df8474c52c525033ab7a4e301bd46444 37890 java optional tomcat6_6.0.32-5_all.deb
 bcc2e8c605d53e733737516b97427113 29550 java optional tomcat6-user_6.0.32-5_all.deb
 5f404234cc7e268ea8c23a0598b57511 3066114 java optional libtomcat6-java_6.0.32-5_all.deb
 2a303ef7672df2a8f124914039fda0cc 194232 java optional libservlet2.5-java_6.0.32-5_all.deb
 946aad466db7a66d64f9ff5c799992ab 256934 doc optional libservlet2.5-java-doc_6.0.32-5_all.deb
 108c2ff87a1b2f13a4887ff970b06673 48252 java optional tomcat6-admin_6.0.32-5_all.deb
 3a0aca3f85ed2d3176fd6ea1082edc10 163204 java optional tomcat6-examples_6.0.32-5_all.deb
 84a2fda937f3381d3ed075ccfbc94e48 546138 doc optional tomcat6-docs_6.0.32-5_all.deb
 dc6cf7ec94152f6af09a3229b16b5bf6 12166 java optional tomcat6-extras_6.0.32-5_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQIcBAEBAgAGBQJOFTlOAAoJECHSBYmXSz6WH2oQALbSlE69xnuguZgaFuM6zGmi
CSHQscDRRHU6PI0isCQr0RysmyLy06cSxUerwwDtSZ8b9QDgpd9xPbjhpAmhhr74
U9kvYZz1uuqnn1Q+okLi74cukfIFY8OpiJLeJ+nnJcZHhSeMSDwBRRrmzrg9BkwM
2vI6x8HEu+/OzIz0eDlOo13Sxx7AHJiMQlenvPDtPdUnDMdY6Jew4BP0R4hEdz8+
/QoSfxRYXBW/Tzb+c8wrj7jV7qXWKyhWzPQAbHZxbAN/6CULVn3nVPKI7MlUXYgP
6WI7ldbqg0GjIwW2smuAzHhFzoqW7cdJsU96nlMGejG2TrUS5N7jtrccWItMzMRd
2pbAWyErxGVTsh0hnwrdSNFvrG8HzxtnVHEN6Al2z2jelusGT+WdhyI761QvoL5O
x0mxHSdoSYMB3lC/MTVbupuqN0jdRcHODZP+0zjrYlOPzZbK3X1dDAl+FLpvtYTV
DU7RQP1dCM4LPSW03PrAWcePyETkHTQprXMO9OR3SzT1UO5lTPArxMV9umrxMICI
rJmbp6j3fO/PKbFQZchX3T7kU5HGK2PcnExXsgFbPFowrTVcobfdVK+oN6kQpiUq
BJeSIC9ibk81VT8vQ3usMVxEYvihLMXaW1qvfc/zzxNdKK6JNarWStcpLSkd1AMI
55bTFSjJiZ/69RZE7UPj
=7Xzz
-----END PGP SIGNATURE-----





Reply sent to tony mancill <tmancill@debian.org>:
You have taken responsibility. (Thu, 07 Jul 2011 05:36:19 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@debian.org>:
Bug acknowledged by developer. (Thu, 07 Jul 2011 05:36:19 GMT) (full text, mbox, link).


Message #20 received at 632882-close@bugs.debian.org (full text, mbox, reply):

From: tony mancill <tmancill@debian.org>
To: 632882-close@bugs.debian.org
Subject: Bug#632882: fixed in tomcat7 7.0.16-3
Date: Thu, 07 Jul 2011 05:33:20 +0000
Source: tomcat7
Source-Version: 7.0.16-3

We believe that the bug you reported is fixed in the latest version of
tomcat7, which is due to be installed in the Debian FTP archive:

libservlet3.0-java-doc_7.0.16-3_all.deb
  to main/t/tomcat7/libservlet3.0-java-doc_7.0.16-3_all.deb
libservlet3.0-java_7.0.16-3_all.deb
  to main/t/tomcat7/libservlet3.0-java_7.0.16-3_all.deb
libtomcat7-java_7.0.16-3_all.deb
  to main/t/tomcat7/libtomcat7-java_7.0.16-3_all.deb
tomcat7-admin_7.0.16-3_all.deb
  to main/t/tomcat7/tomcat7-admin_7.0.16-3_all.deb
tomcat7-common_7.0.16-3_all.deb
  to main/t/tomcat7/tomcat7-common_7.0.16-3_all.deb
tomcat7-docs_7.0.16-3_all.deb
  to main/t/tomcat7/tomcat7-docs_7.0.16-3_all.deb
tomcat7-examples_7.0.16-3_all.deb
  to main/t/tomcat7/tomcat7-examples_7.0.16-3_all.deb
tomcat7-user_7.0.16-3_all.deb
  to main/t/tomcat7/tomcat7-user_7.0.16-3_all.deb
tomcat7_7.0.16-3.debian.tar.gz
  to main/t/tomcat7/tomcat7_7.0.16-3.debian.tar.gz
tomcat7_7.0.16-3.dsc
  to main/t/tomcat7/tomcat7_7.0.16-3.dsc
tomcat7_7.0.16-3_all.deb
  to main/t/tomcat7/tomcat7_7.0.16-3_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 632882@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
tony mancill <tmancill@debian.org> (supplier of updated tomcat7 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Wed, 06 Jul 2011 21:55:39 -0700
Source: tomcat7
Binary: tomcat7-common tomcat7 tomcat7-user libtomcat7-java libservlet3.0-java libservlet3.0-java-doc tomcat7-admin tomcat7-examples tomcat7-docs
Architecture: source all
Version: 7.0.16-3
Distribution: unstable
Urgency: low
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: tony mancill <tmancill@debian.org>
Description: 
 libservlet3.0-java - Servlet 3.0 and JSP 2.2 Java API classes
 libservlet3.0-java-doc - Servlet 3.0 and JSP 2.2 Java API documentation
 libtomcat7-java - Servlet and JSP engine -- core libraries
 tomcat7    - Servlet and JSP engine
 tomcat7-admin - Servlet and JSP engine -- admin web applications
 tomcat7-common - Servlet and JSP engine -- common files
 tomcat7-docs - Servlet and JSP engine -- documentation
 tomcat7-examples - Servlet and JSP engine -- example web applications
 tomcat7-user - Servlet and JSP engine -- tools to create user instances
Closes: 632882
Changes: 
 tomcat7 (7.0.16-3) unstable; urgency=low
 .
   * Team upload.
   * Correct Suggests: for libtcnative-1 (tomcat-native)
   * Add patch for CVE-2011-2204 (Closes: #632882)
Checksums-Sha1: 
 b432d6eeb34e647aaa34d13340101129846921be 2166 tomcat7_7.0.16-3.dsc
 f96fd73f9d47f70ba08503f58d9bce75d6ddc533 41120 tomcat7_7.0.16-3.debian.tar.gz
 4aff3274b9d13aee71bde0e0bb7bf431e78012fb 52350 tomcat7-common_7.0.16-3_all.deb
 571cbed27b052859c76225292f8b329b975c896c 45610 tomcat7_7.0.16-3_all.deb
 3c24182ffc3ad24424415249fb880e385cf2a972 35414 tomcat7-user_7.0.16-3_all.deb
 b8dcfe200d85acad4e4981bace888402922fcc7f 3349220 libtomcat7-java_7.0.16-3_all.deb
 dcbdd481d7be96c822362f7a769f78face4aa39e 299112 libservlet3.0-java_7.0.16-3_all.deb
 74f0e576da5e71bf15f7fcd1e7da7eb7b3f1ed9d 299424 libservlet3.0-java-doc_7.0.16-3_all.deb
 20f6c71ee73072cf926182858a1b38a375fa2fd7 48160 tomcat7-admin_7.0.16-3_all.deb
 b2c4c30436bb719aace9b604c8dc4fa3bd95e158 179934 tomcat7-examples_7.0.16-3_all.deb
 53992b94bfe1cb6bb5312e0f8022f99209443306 577940 tomcat7-docs_7.0.16-3_all.deb
Checksums-Sha256: 
 9acf92c63278a667105e5024822ada1e558d5165058ad438fe1d45a6f3e312ac 2166 tomcat7_7.0.16-3.dsc
 969e66360771b344b419809b0dfec09826469d38f0359dc5312d0f0adb9827e3 41120 tomcat7_7.0.16-3.debian.tar.gz
 9d17f777512ff426cee60e5de235d0103a68ae26d13fc0770facc18b6d003676 52350 tomcat7-common_7.0.16-3_all.deb
 70144954a05904b68c19652409fdd2eed5fe49104458744afedb2a75dad62eb3 45610 tomcat7_7.0.16-3_all.deb
 7cad340ff8484ecef225fc7c80646d09c4e54c88ca4d86418107df9101fb1b7f 35414 tomcat7-user_7.0.16-3_all.deb
 0efefda0db5f91192b5cf86547da5a83e23689ffecf20e0c29baca67ba655e4c 3349220 libtomcat7-java_7.0.16-3_all.deb
 eddab6549ade4040fe28b99ab4bd06b53e10b854e659c2aef1f3aea31cba1bd6 299112 libservlet3.0-java_7.0.16-3_all.deb
 824cfef2d55f96cb1ab0579b320961a53b0d7477b9aa805c59d068f4ef2861a5 299424 libservlet3.0-java-doc_7.0.16-3_all.deb
 9cb1b1dedc13e98ea2038434cf3970c1103583ba12710d26b61f2dfa78e927a3 48160 tomcat7-admin_7.0.16-3_all.deb
 1d405cbf13d8a332848c2052ec2d5001492e5ad4c7acd016491ffd88d486ad49 179934 tomcat7-examples_7.0.16-3_all.deb
 a9f472b074a7cf61b6f8ca3bb0c4d15a77627f07e556e7126037080c18c9607e 577940 tomcat7-docs_7.0.16-3_all.deb
Files: 
 873c02e052d65b8a5bdd6bb4de52405c 2166 java optional tomcat7_7.0.16-3.dsc
 5de2abba9841b1d2fbc0c50f6f1e199b 41120 java optional tomcat7_7.0.16-3.debian.tar.gz
 a5226410d02ec4d0c16cb442a57290ea 52350 java optional tomcat7-common_7.0.16-3_all.deb
 1e1e9df8b71c54e52d18dbea8bc171bb 45610 java optional tomcat7_7.0.16-3_all.deb
 012ef54f62fa378e2ea1995b6d372a0e 35414 java optional tomcat7-user_7.0.16-3_all.deb
 52dac18dc0e6e6e20e52225d9da29ad4 3349220 java optional libtomcat7-java_7.0.16-3_all.deb
 e2be5384211c6b91fbd1a8b2e895180b 299112 java optional libservlet3.0-java_7.0.16-3_all.deb
 51330a78d4958f4083b4b8c6877566b9 299424 doc optional libservlet3.0-java-doc_7.0.16-3_all.deb
 b016e31a5e1d8768f794e0598793b947 48160 java optional tomcat7-admin_7.0.16-3_all.deb
 06f483bf2a60774d48960306682654fd 179934 java optional tomcat7-examples_7.0.16-3_all.deb
 f0c5a38b6870afc3442109825498feeb 577940 doc optional tomcat7-docs_7.0.16-3_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQIcBAEBAgAGBQJOFULYAAoJECHSBYmXSz6We80P/0gaeO/tR3MIrED+LdS8BrLZ
pUJuPePH9x3I9UzPBkUbM0Pl8xGkwN+gBYa7Iyqyr8PocJz1pcBHALQ6DViNXv9R
0msgsh095plMdzY/x7CqMfsQYNV1cSvShFSF6RvtFbD6pdS6wkhQCDQ+1wRU8bRf
4YP7EcB9qbBQI6B8frWggL36CA4iagG+vgkL5ITpRUFpQT08D2gUntFWisGeWeDA
ibH7lR9u3tDhI4q0oWD+yuMsHpVSCRgJ4JHDXktWpdtoy4iFf6x+GUpCpCYi13Ll
x1644wY3BXO1FhYAaG9MRCHXraXTg/YyEoRbT4qamLFMivYUg57xeSuKSsLU9RA4
XuC1jN3sEYP/YTgRVJZiJKOpScRrV75NF7k4zq7VRoE3TkOsXQ7TQkIh4fewBiDT
2tGuAU0cT3Tz71LG38SLK8bam44nNxedNvQKrP1OdxUmSD3c60Bvlzexmrg7Jpkr
4uzvy7tOL7sTTS+9EoqnPk2sn1qIvLCT66azADL3roXvjeKqdY6sN8CQhSx4jXz4
bvLorhsppdSaC9lN3RYTKHxOIjWWwA+1DILe8YE+HGBuutmRgFaWOZUeE8QjAXhg
G81CPNMxrhWZdsYeb9f3aBmvh99EQUBdaxPQLiWTDmJhEWQkB6lCUNurmi9gr8xO
n7gX32MI8KbI1odwjFoC
=hgj7
-----END PGP SIGNATURE-----





Information forwarded to debian-bugs-dist@lists.debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>:
Bug#632882; Package tomcat6. (Mon, 18 Jul 2011 20:27:05 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@inutil.org>:
Extra info received and forwarded to list. Copy sent to Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>. (Mon, 18 Jul 2011 20:27:05 GMT) (full text, mbox, link).


Message #25 received at 632882@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@inutil.org>
To: tony mancill <tmancill@debian.org>
Cc: 632882@bugs.debian.org, Moritz Muehlenhoff <jmm@debian.org>
Subject: Re: Bug#632882: CVE-2011-2204
Date: Mon, 18 Jul 2011 22:21:59 +0200
On Wed, Jul 06, 2011 at 09:49:17PM -0700, tony mancill wrote:
> Hello Moritz,
> 
> Thank you for filing the bug.  I've uploaded an updated tomcat6 package
> for unstable and will get the patch applied for the next tomcat7 upload
> soon.  I'll also look into an upload of 6.0.28 for stable proposed updates.

Sounds good. What's the status of #608286 ?

Cheers,
        Moritz




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Tue, 16 Aug 2011 07:36:36 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 15:13:04 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.