UbuntuUpdates.org

Package "jetty"

Name: jetty

Description:

Java servlet engine and webserver

Latest version: 6.1.24-6ubuntu0.12.04.1
Release: precise (12.04)
Level: updates
Repository: universe
Homepage: http://jetty.mortbay.com/

Links


Download "jetty"


Other versions of "jetty" in Precise

Repository Area Version
base universe 6.1.24-6
security universe 6.1.24-6ubuntu0.12.04.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 6.1.24-6ubuntu0.12.04.1 2012-05-02 12:09:33 UTC

jetty (6.1.24-6ubuntu0.12.04.1) precise-security; urgency=low

  * SECURITY UPDATE: denial of service via many hash collisions
    - debian/patches/CVE-2011-4461.patch: limit number of form parameters
      to avoid a DoS in modules/jetty/src/main/java/org/mortbay/jetty/Request.java,
      modules/jetty/src/main/java/org/mortbay/jetty/handler/ContextHandler.java,
      modules/jetty/src/test/java/org/mortbay/jetty/RequestTest.java,
      modules/util/src/main/java/org/mortbay/util/UrlEncoded.java,
      modules/util/src/test/java/org/mortbay/util/URLEncodedTest.java.
    - CVE-2011-4461

 -- Marc Deslauriers Mon, 23 Apr 2012 09:26:54 -0400

CVE-2011-4461 Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which all



About   -   Send Feedback to @ubuntu_updates