Mageia 2023-0319: tomcat security update
Summary
The updated packages fix security vulnerabilities:
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various
internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11,
from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from
8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of
the recycling process leading to information leaking from the current
request/response to the next. (CVE-2023-42795)
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from
11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from
9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly
parse HTTP trailer headers. A specially crafted, invalid trailer header
could cause Tomcat to treat a single request as multiple requests
leading to the possibility of request smuggling when behind a reverse
proxy. (CVE-2023-45648)
References
- https://bugs.mageia.org/show_bug.cgi?id=32377
- https://www.openwall.com/lists/oss-security/2023/10/10/9
- https://www.openwall.com/lists/oss-security/2023/10/10/10
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42795
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45648
Resolution
MGASA-2023-0319 - Updated tomcat packages fix security vulnerabilities
SRPMS
- 8/core/tomcat-9.0.82-1.mga8
- 9/core/tomcat-9.0.82-1.mga9