* SECURITY UPDATE: privilege escalation via insecure init script
- debian/tomcat7.init: don't follow symlinks when handling the
catalina.out file.
- CVE-2016-1240
* SECURITY REGRESSION: change in behaviour after security update
(LP: #1609819)
- debian/patches/CVE-2015-5345-2.patch: fix using the new
mapperContextRootRedirectEnabled option in
java/org/apache/catalina/connector/MapperListener.java, change
mapperContextRootRedirectEnabled default to true in
java/org/apache/catalina/core/StandardContext.java,
webapps/docs/config/context.xml. This reverts the change in behaviour
following the CVE-2015-5345 security update and was also done
upstream in later releases.
This bug was fixed in the package tomcat7 - 7.0.52-1ubuntu0.7
---------------
tomcat7 (7.0.52-1ubuntu0.7) trusty-security; urgency=medium
* SECURITY UPDATE: privilege escalation via insecure init script tomcat7. init: don't follow symlinks when handling the patches/ CVE-2015- 5345-2. patch: fix using the new textRootRedirec tEnabled option in org/apache/ catalina/ connector/ MapperListener. java, change textRootRedirec tEnabled default to true in org/apache/ catalina/ core/StandardCo ntext.java, docs/config/ context. xml. This reverts the change in behaviour
- debian/
catalina.out file.
- CVE-2016-1240
* SECURITY REGRESSION: change in behaviour after security update
(LP: #1609819)
- debian/
mapperCon
java/
mapperCon
java/
webapps/
following the CVE-2015-5345 security update and was also done
upstream in later releases.
-- Marc Deslauriers <email address hidden> Fri, 16 Sep 2016 09:19:37 -0400