Several security vulnerabilities have been found in Tomcat 9, a Java web server and servlet engine. The update corrects various flaws which can lead to a bypass of security constraints or a denial of service. In addition it fixes a regression that prevented tomcat's start script from detecting installations of OpenJDK 17.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4468-1
Update to latest upstream release in order to fix CVE-2017-9735. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-03954b6dc4 2017-07-08 16:05:01.876275 --------------------------------------------------------------------------------Name : jetty Product : Fedora 25 Version : 9.4.6 Release : 1.v20170531.fc25 URL : https://jetty.org/ Summary : Java Webserver and Servlet Container Description : Jetty is a 100% Java HTTP Server and Servlet Container. This means that you do not need to configure and run a separate web server (like Apache) in order to use Java, servlets and JSPs to generate dynamic content. Jetty is a fully featured web server for static and dynamic content. Unlike separate server/container solutions, this means that your web server and web application run in the same process, without interconnection overheads and complications. Furthermore, as a pure java component, Jetty can be simply included in your application for demonstration, distribution or deployment. Jetty is available on all Java supported platforms. --------------------------------------------------------------------------------Update Information: Update to latest upstream release in order to fix CVE-2017-9735 --------------------------------------------------------------------------------References: [ 1 ] Bug #1464158 - CVE-2017-9735 jetty: Timing channel attack in util/security/Password.java https://bugzilla.redhat.com/show_bug.cgi?id=1464158 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade jetty' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.