Bug#503309: tomcat6: Several security issues in Tomcat

2008-11-08 Thread Dominic Hargreaves
On Fri, Oct 24, 2008 at 05:41:39PM +0200, Moritz Muehlenhoff wrote: > Several vulnerabilities have been fixed in Apache Tomcat 6.0.18, see > below. > > BTW, do we really need two Tomcat versions in Lenny? Is Tomcat 6 > incompatible with 5.5? It doesn't look like the tomcat6 source package actuall

Bug#503309: tomcat6: Several security issues in Tomcat

2008-10-24 Thread Moritz Muehlenhoff
Package: tomcat6 Severity: grave Tags: security Justification: user security hole Several vulnerabilities have been fixed in Apache Tomcat 6.0.18, see below. BTW, do we really need two Tomcat versions in Lenny? Is Tomcat 6 incompatible with 5.5? Cheers, Moritz low: Cross-site script