MGASA-2024-0394 - Updated tomcat tomcat packages fix security vulnerabilities

Publication date: 21 Dec 2024
URL: https://advisories.mageia.org/MGASA-2024-0394.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-50379,
     CVE-2024-54677

RCE due to TOCTOU issue in JSP compilation. (CVE-2024-50379)
DoS in examples web application. (CVE-2024-54677)

References:
- https://bugs.mageia.org/show_bug.cgi?id=33863
- https://www.openwall.com/lists/oss-security/2024/12/17/4
- https://www.openwall.com/lists/oss-security/2024/12/17/5
- https://www.openwall.com/lists/oss-security/2024/12/17/6
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50379
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-54677

SRPMS:
- 9/core/tomcat-9.0.98-1.mga9

Mageia 2024-0394: tomcat tomcat Security Advisory Updates

RCE due to TOCTOU issue in JSP compilation

Summary

RCE due to TOCTOU issue in JSP compilation. (CVE-2024-50379) DoS in examples web application. (CVE-2024-54677)

References

- https://bugs.mageia.org/show_bug.cgi?id=33863

- https://www.openwall.com/lists/oss-security/2024/12/17/4

- https://www.openwall.com/lists/oss-security/2024/12/17/5

- https://www.openwall.com/lists/oss-security/2024/12/17/6

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50379

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-54677

Resolution

MGASA-2024-0394 - Updated tomcat tomcat packages fix security vulnerabilities

SRPMS

- 9/core/tomcat-9.0.98-1.mga9

Severity
Publication date: 21 Dec 2024
URL: https://advisories.mageia.org/MGASA-2024-0394.html
Type: security
CVE: CVE-2024-50379, CVE-2024-54677

Related News