[CLSA-2025:1754650455] tomcat: Fix of CVE-2024-56337
Type:
security
Severity:
Important
Release date:
2025-08-08 10:54:18 UTC
Description:
- CVE-2024-56337: prevent time-of-check time-of-use (TOCTOU) race condition vulnerability by strengthening file validation logic during request handling and closing the gap left by the partial mitigation in CVE‑2024‑50379
Updated packages:
  • tomcat-9.0.62-11.el9_2.3.tuxcare.els13.noarch.rpm
    sha:75f9e394003f0bf9f670dfce5c1a43220e938fdfabea49b93c16bc2b2409b4a2
  • tomcat-admin-webapps-9.0.62-11.el9_2.3.tuxcare.els13.noarch.rpm
    sha:27091728293b4bb9e7bdb65224ae68845cd70675929cc391414bebedc49bbc98
  • tomcat-docs-webapp-9.0.62-11.el9_2.3.tuxcare.els13.noarch.rpm
    sha:76d6eb5e2e36f60cbe8953166c4b9bef2a43736cb18891205b6c72bf497f236b
  • tomcat-el-3.0-api-9.0.62-11.el9_2.3.tuxcare.els13.noarch.rpm
    sha:fea19c2d3ef54daa414fdae143a00045a447d0c5902a9804a61ee674e0fcde6b
  • tomcat-jsp-2.3-api-9.0.62-11.el9_2.3.tuxcare.els13.noarch.rpm
    sha:8245ff32be64b46e1eaac480d748b795088bd1707b609fd0ba4491bc96ccd1b6
  • tomcat-lib-9.0.62-11.el9_2.3.tuxcare.els13.noarch.rpm
    sha:4f7833685760c82377f5f63def93f45cc9fb88290f8282ee4e7b22748d3d099d
  • tomcat-servlet-4.0-api-9.0.62-11.el9_2.3.tuxcare.els13.noarch.rpm
    sha:cb666daaa8d04d080290b00842dace9233453bcdaff05b002f232a60ee4d5330
  • tomcat-webapps-9.0.62-11.el9_2.3.tuxcare.els13.noarch.rpm
    sha:6ac5032b4a20b042d6d924fe62398040876d8b55c5f99c156e1534db82e1d205
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.