Debian Security Advisory
DSA-3842-1 tomcat7 -- security update
- Date Reported:
- 03 May 2017
- Affected Packages:
- tomcat7
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2017-5647, CVE-2017-5648.
- More information:
-
Two vulnerabilities were discovered in tomcat7, a servlet and JSP engine.
- CVE-2017-5647
Pipelined requests were processed incorrectly, which could result in some responses appearing to be sent for the wrong request.
- CVE-2017-5648
Some application listeners calls were issued against the wrong objects, allowing untrusted applications running under a SecurityManager to bypass that protection mechanism and access or modify information associated with other web applications.
For the stable distribution (jessie), these problems have been fixed in version 7.0.56-3+deb8u10.
For the upcoming stable (stretch) and unstable (sid) distributions, these problems have been fixed in version 7.0.72-3.
We recommend that you upgrade your tomcat7 packages.
- CVE-2017-5647