The host name verification in Tomcat when using TLS with the WebSocket client was missing. It is now enabled by default. For Debian 8 "Jessie", this problem has been fixed in version . Package : tomcat7 Version : 7.0.56-3+really7.0.90-1 CVE ID : CVE-2018-8034 The host name verification in Tomcat when using TLS with the WebSocket client was missing. It is now enabled by default. For Debian 8 "Jessie", this problem has been fixed in version 7.0.56-3+really7.0.90-1. We recommend that you upgrade your tomcat7 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS has released a security update for Tomcat7 focusing on TLS host name verification. It is advisable to perform an upgrade to enhance security.. Tomcat7 Update, Debian LTS Security, Host Name Verification, TLS WebSocket, Security Fix. . Severity: Critical. LinuxSecurity.com Team
The update for curl in DSA-2798-1 uncovered a regression affecting the curl command line tool behaviour (#729965). This update disables host verification too when using the --insecure option. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2798-2
Get the latest Linux and open source security news straight to your inbox.