DSA-3720-1 tomcat8 -- security update

Related Vulnerabilities: CVE-2016-0762   CVE-2016-5018   CVE-2016-6794   CVE-2016-6796   CVE-2016-6797  

Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, which may result in possible timing attacks to determine valid user names, bypass of the SecurityManager, disclosure of system properties, unrestricted access to global resources, arbitrary file overwrites, and potentially escalation of privileges. For the stable distribution (jessie), these problems have been fixed in version 8.0.14-1+deb8u4. We recommend that you upgrade your tomcat8 packages.

Debian Security Advisory

DSA-3720-1 tomcat8 -- security update

Date Reported:
21 Nov 2016
Affected Packages:
tomcat8
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 840685.
In Mitre's CVE dictionary: CVE-2016-0762, CVE-2016-5018, CVE-2016-6794, CVE-2016-6796, CVE-2016-6797.
More information:

Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, which may result in possible timing attacks to determine valid user names, bypass of the SecurityManager, disclosure of system properties, unrestricted access to global resources, arbitrary file overwrites, and potentially escalation of privileges.

For the stable distribution (jessie), these problems have been fixed in version 8.0.14-1+deb8u4.

We recommend that you upgrade your tomcat8 packages.