[CLSA-2023:1687469807] Fix CVE(s): CVE-2021-41079, CVE-2021-25122
Type:
security
Severity:
Important
Release date:
2023-06-22 21:36:52 UTC
Description:
* SECURITY UPDATE: Apache Tomcat h2c request mix-up - debian/patches/CVE-2021-25122.patch: Simplify the code and fix an edge case for BZ 64830 - CVE-2021-25122 * SECURITY UPDATE: Denial of Service for NIO+OpenSSL or NIO2+OpenSSL TLS configurations - debian/patches/CVE-2021-41079.patch: Improve robustness - CVE-2021-41079
Updated packages:
  • libtomcat8-embed-java_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb
    sha:6d83cc3f9c017e46f74c7d21020387409d7b7451
  • libtomcat8-java_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb
    sha:80348aec79fdcf3f286aa8ee83cb4c29991710fa
  • tomcat8_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb
    sha:fab233ce6e0d6768a5aa1506194a82b4d68ec082
  • tomcat8-admin_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb
    sha:8012398492f94d291f17cb9cc68cb25d3253102a
  • tomcat8-common_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb
    sha:511199abe32c6a9bf6d7e3dc5566d991d5a3e6ae
  • tomcat8-docs_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb
    sha:be66ddb7784a9ece4a4eb65ac507308d20c600bb
  • tomcat8-examples_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb
    sha:43ef847b460e85425f53dc33c86461aac4131572
  • tomcat8-user_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb
    sha:91175cc151e278cb4e3208fb9eab400a1965ca5d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.