MGASA-2023-0319 - Updated tomcat packages fix security vulnerabilities

Publication date: 15 Nov 2023
URL: https://advisories.mageia.org/MGASA-2023-0319.html
Type: security
Affected Mageia releases: 8, 9
CVE: CVE-2023-42795,
     CVE-2023-45648

The updated packages fix security vulnerabilities:

Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various
internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11,
from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from
8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of
the recycling process leading to information leaking from the current
request/response to the next. (CVE-2023-42795)

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from
11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from
9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly
parse HTTP trailer headers. A specially crafted, invalid trailer header
could cause Tomcat to treat a single request as multiple requests
leading to the possibility of request smuggling when behind a reverse
proxy. (CVE-2023-45648)

References:
- https://bugs.mageia.org/show_bug.cgi?id=32377
- https://www.openwall.com/lists/oss-security/2023/10/10/9
- https://www.openwall.com/lists/oss-security/2023/10/10/10
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42795
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45648

SRPMS:
- 8/core/tomcat-9.0.82-1.mga8
- 9/core/tomcat-9.0.82-1.mga9

Mageia 2023-0319: tomcat security update

The updated packages fix security vulnerabilities: Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 throug...

Summary

The updated packages fix security vulnerabilities:
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. (CVE-2023-42795)
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. (CVE-2023-45648)

References

- https://bugs.mageia.org/show_bug.cgi?id=32377

- https://www.openwall.com/lists/oss-security/2023/10/10/9

- https://www.openwall.com/lists/oss-security/2023/10/10/10

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42795

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45648

Resolution

MGASA-2023-0319 - Updated tomcat packages fix security vulnerabilities

SRPMS

- 8/core/tomcat-9.0.82-1.mga8

- 9/core/tomcat-9.0.82-1.mga9

Severity
Publication date: 15 Nov 2023
URL: https://advisories.mageia.org/MGASA-2023-0319.html
Type: security
CVE: CVE-2023-42795, CVE-2023-45648

Related News