Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 10: DLA-3617-1 Critical: Tomcat9 Denial of Service Attacks

debian lts
Calendar Grey October 13, 2023
Dist Debian Esm H88
Debian LTS advisory DLA-3617-1 recommends upgrading tomcat9 to fix vulnerabilities including remote code execution and session fixation risks for better security
Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine

Summary

CVE-2023-24998

Denial of service. Tomcat uses a packaged renamed copy of Apache Commons
FileUpload to provide the file upload functionality defined in the Jakarta
Servlet specification. Apache Tomcat was, therefore, also vulnerable to the
Commons FileUpload vulnerability CVE-2023-24998 as there was no limit to
the number of request parts processed. This resulted in the possibility of
an attacker triggering a DoS with a malicious upload or series of uploads.

CVE-2023-41080

Open redirect. If the ROOT (default) web application is configured to use
FORM authentication then it is possible that a specially crafted URL could
be used to trigger a redirect to an URL of the attackers choice.

CVE-2023-42795

Information Disclosure. When recycling various internal objects, including
the request and the response, prior to re-use by the next request/response,
an error could cause Tomcat to skip some parts of the recycling process

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: tomcat9
Version: 9.0.31-1~deb10u9
CVE ID: CVE-2023-24998 CVE-2023-41080 CVE-2023-42795 CVE-2023-44487

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here