Debian Security Advisory 1312-1 – It was discovered that the Apache 1.3 connector for the Tomcat Java servlet engine decoded request URLs multiple times, which can lead to information disclosure.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/57225/dsa-1312-1.txt
Source: https://packetstormsecurity.com/files/57225/Debian-Linux-Security-Advisory-1312-1.html