Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2021:3602-1 Important Tomcat Security Update: Denial Of Service

suse
Calendar Grey November 3, 2021
Dist Suse Esm H88
This critical SUSE upgrade addresses numerous MongoDB vulnerabilities to improve safety and uphold system stability.
An update that solves three vulnerabilities and has one errata is now available

Summary

This update for tomcat, javapackages-tools fixes the following issue: Security issue fixed: - CVE-2021-30640: Escape parameters in JNDI Realm queries (bsc#1188279). - CVE-2021-33037: Process T-E header from both HTTP 1.0 and HTTP 1.1. clients (bsc#1188278). - CVE-2021-41079: Fixed a denial of service caused by an unexpected TLS packet (bsc#1190558). Non-security issues fixed: - Add requires and conflicts to avoid the usage of the incompatible 'Java 11' with 'Tomcat'. (bsc#1185476) - Rebuild javapackages-tools to fix a missing package on s390. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9:

References

#1185476 #1188278 #1188279 #1190558

Cross- CVE-2021-30640 CVE-2021-33037 CVE-2021-41079

CVSS scores:

CVE-2021-30640 (NVD) : 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N

CVE-2021-33037 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CVE-2021-41079 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

SUSE OpenStack Cloud Crowbar 9

SUSE OpenStack Cloud 9

SUSE Linux Enterprise Server for SAP 12-SP4

SUSE Linux Enterprise Server 12-SP5

SUSE Linux Enterprise Server 12-SP4-LTSS

https://www.suse.com/security/cve/CVE-2021-30640.html

https://www.suse.com/security/cve/CVE-2021-33037.html

https://www.suse.com/security/cve/CVE-2021-41079.html

https://bugzilla.suse.com/1185476

https://bugzilla.suse.com/1188278

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:3602-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here