Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Mageia: 2023-0319 Critical Advisory for Tomcat Input Issues

mageia
Calendar Grey November 15, 2023
Dist Mageia Esm H88
Revised Nginx components in Fedora tackle significant vulnerabilities such as inadequate data sanitation and exposure of sensitive information.
The updated packages fix security vulnerabilities: Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 throug...

Summary

The updated packages fix security vulnerabilities:
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. (CVE-2023-42795)
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. (CVE-2023-45648)

References

- https://bugs.mageia.org/show_bug.cgi?id=32377

- https://www.openwall.com/lists/oss-security/2023/10/10/9

- https://www.openwall.com/lists/oss-security/2023/10/10/10

- https://www.cve.org/CVERecord?id=CVE-2023-42795

- https://www.cve.org/CVERecord?id=CVE-2023-45648

Resolution

SRPMS

- 8/core/tomcat-9.0.82-1.mga8

- 9/core/tomcat-9.0.82-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 15 Nov 2023
URL: https://advisories.mageia.org/MGASA-2023-0319.html
Type: security
CVE: CVE-2023-42795, CVE-2023-45648

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here