Debian Security Advisory

DSA-3787-1 tomcat7 -- security update

Date Reported:
13 Feb 2017
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 854551.
In Mitre's CVE dictionary: CVE-2017-6056.
More information:

It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop.

For the stable distribution (jessie), this problem has been fixed in version 7.0.56-3+deb8u8.

We recommend that you upgrade your tomcat7 packages.