Bug#866128: tomcat 8 critical bug

Luigi Canali lcanali at fedcms.com
Tue Jun 27 16:09:52 UTC 2017


Package: tomcat8
Version: 8.0.14-1+deb8u5

The current Jessie packages for Tomcat 8 has a bug that really should be
taken care of:

https://bz.apache.org/bugzilla/show_bug.cgi?id=57544

when this bug kicks in, the JVM starts stacking up threads to the point
where the machine becomes unusable - in essence a self-induced denial of
service.

Fortunately the bug has been fixed in Tomcat 8.0.19 or later

I'm requesting that tomcat 8 debian jessie packages get updated at least to
version 8.0.19.

thanks!
Luigi

-- 



Luigi Canali, PMP, GSLC
_________________________________________
FedCMS
(301) 537-9009 - mobile
(202) 318-7628 - fax
LCanali at FedCMS.com
www.FedCMS.com



______________________________________________________________________

Confidentiality Notice: The information contained in this message is
intended only for the use of the
addressee, and should be considered confidential and/or privileged. If the
reader of this message is not the intended recipient, or the employee or
agent responsible to deliver it to the intended recipient, you are hereby
notified that any dissemination, distribution or copying of this
communication and its contents is strictly prohibited.  If you have
received this communication in error, please notify the sender immediately.
______________________________________________________________________
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/pkg-java-maintainers/attachments/20170627/55295e77/attachment.html>


More information about the pkg-java-maintainers mailing list