ubuntu/+source/tomcat6:applied/ubuntu/quantal-security

Last commit made on 2013-05-29
Get this branch:
git clone -b applied/ubuntu/quantal-security https://git.launchpad.net/ubuntu/+source/tomcat6
Members of Ubuntu Server Dev import team can upload to this branch. Log in for directions.

Branch merges

Branch information

Name:
applied/ubuntu/quantal-security
Repository:
lp:ubuntu/+source/tomcat6

Recent commits

795aa4e... by Jamie Strandboge on 2013-05-28

Import patches-applied version 6.0.35-5ubuntu0.1 to applied/ubuntu/quantal-security

Imported using git-ubuntu import.

Changelog parent: a06cdca1c46f878e165ce84de75a625f73c1d4cf
Unapplied parent: fdfd7907ee0c37c38d5f2702868a290d624eb1f3

New changelog entries:
  [ Christian Kuersteiner ]
  * SECURITY UPDATE: denial of service via large header data
    - debian/patches/0012-CVE-2012-2733.patch: improve size logic in
      java/org/apache/coyote/http11/InternalNioInputBuffer.java.
    - CVE-2012-2733
    - LP: #1166649
  * SECURITY UPDATE: security-constraint bypass with FORM auth
    - debian/patches/CVE-2012-3546.patch: remove unneeded code in
      java/org/apache/catalina/realm/RealmBase.java.
    - CVE-2012-3546
  * SECURITY UPDATE: CSRF bypass via request with no session identifier
    - debian/patches/CVE-2012-4431.patch: check for session identifier in
      java/org/apache/catalina/filters/CsrfPreventionFilter.java.
    - CVE-2012-4431
  * SECURITY UPDATE: denial of service with NIO connector
    - debian/patches/CVE-2012-4534.patch: properly handle connection breaks
      in java/org/apache/tomcat/util/net/NioEndpoint.java.
    - CVE-2012-4534
  [ Jamie Strandboge ]
  * SECURITY UPDATE: multiple HTTP Digest Access Authentication flaws
    - debian/patches/0013-CVE-2012-588x.patch: disable caching of an
      authenticated user in the session by default, track server rather
      than client nonces, better handling of stale nonce values in
      java/org/apache/catalina/authenticator/DigestAuthenticator.java.
      Patch from Marc Deslauriers.
    - CVE-2012-3439
    - CVE-2012-5885
    - CVE-2012-5886
    - CVE-2012-5887
  * SECURITY UPDATE: denial of service via chunked transfer encoding
    - debian/patches/CVE-2012-3544.patch: properly parse CRLF in requests
      in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java.
      Patch from Marc Deslauriers.
    - CVE-2012-3544
  * SECURITY UPDATE: FORM authentication request injection
    - debian/patches/CVE-2013-2067.patch: properly change session ID
      in java/org/apache/catalina/authenticator/FormAuthenticator.java.
      Patch from Marc Deslauriers.
    - CVE-2013-2067

fdfd790... by Jamie Strandboge on 2013-05-28

fix FORM authentication request injection

Gbp-Pq: CVE-2013-2067.patch.

5633bcf... by Jamie Strandboge on 2013-05-28

fix denial of service via chunked transfer encoding

Gbp-Pq: CVE-2012-3544.patch.

727abae... by Jamie Strandboge on 2013-05-28

fix denial of service with NIO connector

Gbp-Pq: CVE-2012-4534.patch.

8837127... by Jamie Strandboge on 2013-05-28

fix CSRF bypass via request with no session identifier

Gbp-Pq: CVE-2012-4431.patch.

fead624... by Jamie Strandboge on 2013-05-28

fix security-constraint bypass with FORM auth

Gbp-Pq: CVE-2012-3546.patch.

907bfc1... by Jamie Strandboge on 2013-05-28

fix multiple HTTP Digest Access Authentication flaws

Gbp-Pq: 0013-CVE-2012-588x.patch.

0879546... by Jamie Strandboge on 2013-05-28

fix denial of service via large header data

Gbp-Pq: 0012-CVE-2012-2733.patch.

b5d8472... by Jamie Strandboge on 2013-05-28

fix regression from the CVE-2012-0022 security fix that

Gbp-Pq: 0011-CVE-2012-0022-regression-fix.patch.

b669489... by Jamie Strandboge on 2013-05-28

[PATCH] Use java.security.policy file in catalina.sh

Gbp-Pq: 0010-Use-java.security.policy-file-in-catalina.sh.patch.