Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
203

Mageia 8: 2023-0138 Critical: Tomcat Information Disclosure and Fixes

Information disclosure due to concurrency bug (CVE-2021-43980) Fix for CVE-2020-9484 introduced a time of check, time of use vulnerability (CVE-2022-23181) Correct documentation to warn of use over untrusted networks. (CVE-2022-29885) . MGASA-2023-0138 - Updated tomcat packages fix security vulnerability Publication date: 15 Apr 2023 URL: https://advisories.mageia.org/MGASA-2023-0138.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-43980, CVE-2022-23181, CVE-2022-29885, CVE-2022-34305, CVE-2022-42252, CVE-2022-45143, CVE-2023-24998, CVE-2023-28708 Information disclosure due to concurrency bug (CVE-2021-43980) Fix for CVE-2020-9484 introduced a time of check, time of use vulnerability (CVE-2022-23181) Correct documentation to warn of use over untrusted networks. (CVE-2022-29885) Correct documentation showing use of XSS vulnerability. (CVE-2022-34305) Fix to reject invalid Content-Length header (CVE-2022-42252) Fix escaping of the type, message or description values. (CVE-2022-45143) Fix FileUpload limiting of the number of request parts to be processed to prevent the possibility of an attacker triggering a DoS (CVE-2023-24998) Fix setting of session cookie secure attribute when using RemoteIpFilter with X-Forwarded-Proto header set to https (CVE-2023-28708) Obsolete tomcat-jsvc References: - https://bugs.mageia.org/show_bug.cgi?id=30113 - https://lists.suse.com/pipermail/sle-security-updates/2022-March/010339.html - https://lists.suse.com/pipermail/sle-security-updates/2022-April/010734.html - https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.65 - https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.62 - https://lists.debian.org/debian-lts-announce/2022/10/msg00029.html - https://lists.debian.org/debian-security-announce/2022/msg00235.html - https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.68 - https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.69 -https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.71 - https://lists.suse.com/pipermail/sle-security-updates/2023-March/014018.html - https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.72 - https://www.cve.org/CVERecord?id=CVE-2021-43980 - https://www.cve.org/CVERecord?id=CVE-2022-23181 - https://www.cve.org/CVERecord?id=CVE-2022-29885 - https://www.cve.org/CVERecord?id=CVE-2022-34305 - https://www.cve.org/CVERecord?id=CVE-2022-42252 - https://www.cve.org/CVERecord?id=CVE-2022-45143 - https://www.cve.org/CVERecord?id=CVE-2023-24998 - https://www.cve.org/CVERecord?id=CVE-2023-28708 SRPMS: - 8/core/tomcat-9.0.73-1.1.mga8 . Newly released Mageia tomcat updates patch significant security flaws identified as of April 15, 2023.. Mageia Security Update,Tcp Vulnerabilities,Mageia 2023 Advisory,Tcp Concurrency Bug,Application Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 15, 2023 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here