Mailing the story:
Debian alert: New tomcat packages fix information exposure and cross site scripting
The developers of tomcat discovered several problems in tomcat version
3.x. The Common Vulnerabilities and Exposures project identifies the
following problems: