Package: tomcat6-common
Version: 6.0.35-1
Severity: grave
Tags: security

/usr/share/tomcat6/bin/catalina.sh line 276 reads

        -Djava.security.policy=="$CATALINA_BASE"/work/catalina.policy \

The double = looks like a mistake. When running with -security, the
policy will not get loaded.

Admittedly, I haven't tested it here, but I figured I should still
file a bug because this just looks too obvious. If the second = is on
purpose there, some comment should document that.

Affected are both squeeze and unstable/testing.

Christoph
-- 
[email protected] | http://www.df7cb.de/

Attachment: signature.asc
Description: Digital signature

_______________________________________________
Secure-testing-team mailing list
[email protected]
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-team

Reply via email to