SUSE: 2019:1693-1 moderate: tomcat
Summary
This update for tomcat to version 9.0.20 fixes the following issues: Security issues fixed: - CVE-2019-0199: Fixed a denial of service in the HTTP/2 implementation related to streams with excessive numbers of SETTINGS frames (bsc#1131055). - CVE-2019-0221: Fixed a cross site scripting vulnerability with the SSI printenv command (bsc#1136085). Non-security issues fixed: - Increase maximum number of threads and open files for tomcat (bsc#1111966). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Web Scripting 15: zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-2019-1693=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-16...
Read the Full AdvisoryReferences
#1111966 #1131055 #1136085
Cross- CVE-2019-0199 CVE-2019-0221
Affected Products:
SUSE Linux Enterprise Module for Web Scripting 15
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15
https://www.suse.com/security/cve/CVE-2019-0199.html
https://www.suse.com/security/cve/CVE-2019-0221.html
https://bugzilla.suse.com/1111966
https://bugzilla.suse.com/1131055
https://bugzilla.suse.com/1136085