[ALSA-2023:5928] tomcat security update

Severity Important
Affected Packages 8
CVEs 1

tomcat security update

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.

Security Fix(es):

  • HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

ID
ALSA-2023:5928
Severity
important
URL
https://errata.almalinux.org/ALSA-2023:5928.html
Published
2023-10-19T00:00:00
(11 months ago)
Modified
2023-10-20T11:16:24
(11 months ago)
Rights
Copyright 2023 AlmaLinux OS
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/almalinux/tomcat?arch=noarch&distro=almalinux-8.8 almalinux tomcat < 9.0.62-5.el8_8.2 almalinux-8.8 noarch
Affected pkg:rpm/almalinux/tomcat-webapps?arch=noarch&distro=almalinux-8.8 almalinux tomcat-webapps < 9.0.62-5.el8_8.2 almalinux-8.8 noarch
Affected pkg:rpm/almalinux/tomcat-servlet-4.0-api?arch=noarch&distro=almalinux-8.8 almalinux tomcat-servlet-4.0-api < 9.0.62-5.el8_8.2 almalinux-8.8 noarch
Affected pkg:rpm/almalinux/tomcat-lib?arch=noarch&distro=almalinux-8.8 almalinux tomcat-lib < 9.0.62-5.el8_8.2 almalinux-8.8 noarch
Affected pkg:rpm/almalinux/tomcat-jsp-2.3-api?arch=noarch&distro=almalinux-8.8 almalinux tomcat-jsp-2.3-api < 9.0.62-5.el8_8.2 almalinux-8.8 noarch
Affected pkg:rpm/almalinux/tomcat-el-3.0-api?arch=noarch&distro=almalinux-8.8 almalinux tomcat-el-3.0-api < 9.0.62-5.el8_8.2 almalinux-8.8 noarch
Affected pkg:rpm/almalinux/tomcat-docs-webapp?arch=noarch&distro=almalinux-8.8 almalinux tomcat-docs-webapp < 9.0.62-5.el8_8.2 almalinux-8.8 noarch
Affected pkg:rpm/almalinux/tomcat-admin-webapps?arch=noarch&distro=almalinux-8.8 almalinux tomcat-admin-webapps < 9.0.62-5.el8_8.2 almalinux-8.8 noarch
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...