Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
This update for Jetty, a Java servlet engine and web server, addresses a protocol-level vulnerability in HTTP/2 support also referred to as "MadeYouReset". . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6005-1
The security update DLA-4106-1 for jetty9 incorrectly required an unavailable dependency on sysvinit-utils > = 3.05 when installing the jetty9 binary package. This issue has been addressed by reverting back to requiring only the lsb-base binary package. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4106-2 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Markus Koschany April 05, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : jetty9 Version : 9.4.57-0+deb11u2 The security update DLA-4106-1 for jetty9 incorrectly required an unavailable dependency on sysvinit-utils > = 3.05 when installing the jetty9 binary package. This issue has been addressed by reverting back to requiring only the lsb-base binary package. For Debian 11 bullseye, this problem has been fixed in version 9.4.57-0+deb11u2. We recommend that you upgrade your jetty9 packages. For the detailed security status of jetty9 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/jetty9 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Resolved compatibility challenge in the latest jetty9 package for Debian. Update suggested for optimal performance.. jetty9 update, debian security, dependency issue, regression fix. . Severity: Low. LinuxSecurity.com Team
Jetty 9 is a Java based web server and servlet engine. Several security vulnerabilities have been discovered which may allow remote attackers to cause a denial of service by repeatedly sending crafted requests which can trigger OutofMemory errors and exhaust the server's memory. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5894-1
Jetty 9 is a Java based web server and servlet engine. It was discovered that remote attackers may leave many HTTP/2 connections in ESTABLISHED state (not closed), TCP congested and idle. Eventually the server will stop accepting new connections from valid clients which can cause a denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5664-1
The recent update of jetty9, released as DLA 3641-1, caused a regression in PuppetDB, a major component of Puppet that helps you manage and automate the configuration of servers. More specifically another package, trapperkeeper- webserver-jetty9-clojure, still used the deprecated SslContextFactory class . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3647-1
Two remotely exploitable security vulnerabilities were discovered in Jetty 9, a Java based web server and servlet engine. The HTTP/2 protocol implementation did not sufficiently verify if HPACK header . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3641-1
Steven Seeley discovered that in jetty, a Java servlet engine and webserver, requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory. An attacker may access sensitive information regarding the implementation of a web . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2688-1
Get the latest Linux and open source security news straight to your inbox.