tomcat6: CVE-2014-0227: HTTP request smuggling or DoS by streaming malformed data

2015-05-14 Thread Santiago Ruano Rincón
Source: tomcat6 Version: 6.0.35-6+deb7u1 Severity: important Tags: security patch upstream fixed-upstream Hi there, The following vulnerability affects current tomcat 6.x in squeeze and wheezy. According to CVE-2014-0227 [cve], "Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before

CVE-2014-0230: non-persistent DoS attack by feeding data aborting an upload

2015-05-14 Thread Santiago Ruano Rincón
Source: tomcat6 Version: 6.0.41-2+squeeze6 Severity: normal Tags: security upstream fixed-upstream Hello, The following vulnerability affects tomcat6 in squeeze and wheezy. CVE-2014-0230 [cve]: Tomcat permits a limited Denial of Service. I have prepared the attached patch for the 6.0.41-2+squee

Re: squeeze update of dnsmasq?

2015-05-14 Thread Simon Kelley
Hi Raphael. I'm over-committed trying to get the long-overdue 2.73 release of dnsmasq out at the moment, so if the LTS team could handle the Debian mechanics of this, that would really help me. I can confirm that the patch which fixes the issue is here http://thekelleys.org.uk/gitweb/?p=dnsmasq