- ------------------------------------------------------------------------- Debian LTS Advisory DLA-2407-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Chris Lamb October 14, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : tomcat8 Version : 8.5.54-0+deb9u4 CVE ID : CVE-2020-13943 It was discovered that there was an issue in Apache Tomcat 8, the Java application server. An excessive number of concurrent streams could have resulted in users seeing responses for unexpected resources. For Debian 9 "Stretch", this problem has been fixed in version 8.5.54-0+deb9u4. We recommend that you upgrade your tomcat8 packages. For the detailed security status of tomcat8 please refer to its security tracker page at: Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS