Debian Security Advisory
DSA-3843-1 tomcat8 -- security update
- Date Reported:
- 03 May 2017
- Affected Packages:
- tomcat8
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 860068, Bug 860069.
In Mitre's CVE dictionary: CVE-2017-5647, CVE-2017-5648. - More information:
-
Two vulnerabilities were discovered in tomcat8, a servlet and JSP engine.
- CVE-2017-5647
Pipelined requests were processed incorrectly, which could result in some responses appearing to be sent for the wrong request.
- CVE-2017-5648
Some application listeners calls were issued against the wrong objects, allowing untrusted applications running under a SecurityManager to bypass that protection mechanism and access or modify information associated with other web applications.
For the stable distribution (jessie), these problems have been fixed in version 8.0.14-1+deb8u9.
For the upcoming stable (stretch) and unstable (sid) distributions, these problems have been fixed in version 8.5.11-2.
We recommend that you upgrade your tomcat8 packages.
- CVE-2017-5647