Debian has issued an update for tomcat5.5. This fixes some vulnerabilities and a security issue, which can be exploited by malicious, local users to bypass certain security restrictions, and by malicious people to disclose sensitive information and conduct cross-site scripting attacks.