Debian Security Advisory

DSA-3842-1 tomcat7 -- security update

Date Reported:
03 May 2017
Affected Packages:
Security database references:
In Mitre's CVE dictionary: CVE-2017-5647, CVE-2017-5648.
More information:

Two vulnerabilities were discovered in tomcat7, a servlet and JSP engine.

  • CVE-2017-5647

    Pipelined requests were processed incorrectly, which could result in some responses appearing to be sent for the wrong request.

  • CVE-2017-5648

    Some application listeners calls were issued against the wrong objects, allowing untrusted applications running under a SecurityManager to bypass that protection mechanism and access or modify information associated with other web applications.

For the stable distribution (jessie), these problems have been fixed in version 7.0.56-3+deb8u10.

For the upcoming stable (stretch) and unstable (sid) distributions, these problems have been fixed in version 7.0.72-3.

We recommend that you upgrade your tomcat7 packages.