Alerts This Week
Warning Icon 1 1,179
Alerts This Week
Warning Icon 1 1,179

SUSE: 2020:2611-1 Moderate: Tomcat HTTP Request Smuggling and DoS

suse
Calendar Grey September 11, 2020
Dist Suse Esm H88
SUSE has released a security update for nginx addressing critical buffer overflow and denial of service vulnerabilities. Access the patch information immediately.
An update that fixes two vulnerabilities is now available

Summary

This update for tomcat fixes the following issues: - CVE-2020-1935: Fixed an HTTP request smuggling vulnerability (bsc#1164860). - CVE-2020-13935: Fixed a WebSocket DoS (bsc#1174117). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2020-2611=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2020-2611=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2020-2611=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2020-2611=1 - SUSE Linux Enterprise Server for SAP 12-SP2:

References

#1164860 #1174117

Cross- CVE-2020-13935 CVE-2020-1935

Affected Products:

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 8

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP3

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP3-LTSS

SUSE Linux Enterprise Server 12-SP3-BCL

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP2-BCL

SUSE Enterprise Storage 5

HPE Helion Openstack 8

https://www.suse.com/security/cve/CVE-2020-13935.html

https://www.suse.com/security/cve/CVE-2020-1935.html

https://bugzilla.suse.com/1164860

https://bugzilla.suse.com/1174117

Announcement ID: SUSE-SU-2020:2611-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here