Just to make it easier, please add any extra CVEs for tomcat7 to this bug and create a separate bug for tomcat6. I'll adjust the summary and description.
As for CVE-2012-2733, there is no upstream fix that I am aware of, so feel free to skip it (unless you find a patch for it-- if so, please let us know :). ** Also affects: tomcat7 (Ubuntu Oneiric) Importance: Undecided Status: New ** Also affects: tomcat7 (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: tomcat7 (Ubuntu Raring) Importance: Undecided Status: New ** Also affects: tomcat7 (Ubuntu Quantal) Importance: Undecided Status: New ** Changed in: tomcat7 (Ubuntu Raring) Status: New => Fix Released ** Changed in: tomcat7 (Ubuntu Quantal) Status: New => Fix Released ** Changed in: tomcat7 (Ubuntu Precise) Status: New => Triaged ** Changed in: tomcat7 (Ubuntu Oneiric) Status: New => Triaged ** Summary changed: - Parameter Handling Denial of Service in Oneiric + Multiple open vulnerabilities in tomcat7 in 12.04 and 11.10 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to tomcat7 in Ubuntu. https://bugs.launchpad.net/bugs/1115053 Title: Multiple open vulnerabilities in tomcat7 in 12.04 and 11.10 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/tomcat7/+bug/1115053/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs