Mageia 2024-0394: tomcat tomcat Security Advisory Updates
Summary
RCE due to TOCTOU issue in JSP compilation. (CVE-2024-50379)
DoS in examples web application. (CVE-2024-54677)
References
- https://bugs.mageia.org/show_bug.cgi?id=33863
- https://www.openwall.com/lists/oss-security/2024/12/17/4
- https://www.openwall.com/lists/oss-security/2024/12/17/5
- https://www.openwall.com/lists/oss-security/2024/12/17/6
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50379
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-54677
Resolution
MGASA-2024-0394 - Updated tomcat tomcat packages fix security vulnerabilities
SRPMS
- 9/core/tomcat-9.0.98-1.mga9