Please update Tomcat7 in trusty-security to >= 7.0.55 to enable easier server info hiding

Bug #1400517 reported by Dave Myron
274
This bug affects 4 people
Affects Status Importance Assigned to Milestone
tomcat7 (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

Tomcat 7.0.55 introduced the ability to more easily hide information leaks by adding some configuration to error valve configurations. Enabling these obfuscations help to minimize information sent out when an error is reached.

Please update the trusty-security (& related) versions of tomcat7 to at least 7.0.55 (current version as of 2014-12-08 is 7.0.57)

Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in tomcat7 (Ubuntu):
status: New → Confirmed
Revision history for this message
Luis Arias (kaaloo) wrote :

There are definitely some security issues marked "Important" and one concerning Denial of service since 7.0.52:

http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.55

Robie Basak (racb)
information type: Public → Public Security
Alex Kiss (sysrex)
Changed in tomcat7 (Ubuntu):
assignee: nobody → Alex Kiss (sysrex)
assignee: Alex Kiss (sysrex) → nobody
Alex Kiss (sysrex)
Changed in tomcat7 (Ubuntu):
assignee: nobody → Alex Kiss (sysrex)
Changed in tomcat7 (Ubuntu):
assignee: Alex Kiss (sysrex) → nobody
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.