Package        : tomcat7
Version        : 7.0.56-3+really7.0.90-1
CVE ID         : CVE-2018-8034

The host name verification in Tomcat when using TLS with the WebSocket
client was missing. It is now enabled by default.

For Debian 8 "Jessie", this problem has been fixed in version
7.0.56-3+really7.0.90-1.

We recommend that you upgrade your tomcat7 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-1453-1: tomcat7 security update

July 30, 2018
The host name verification in Tomcat when using TLS with the WebSocket client was missing

Summary

We recommend that you upgrade your tomcat7 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : tomcat7
Version : 7.0.56-3+really7.0.90-1
CVE ID : CVE-2018-8034

Related News