[CLSA-2023:1689010064] Fix CVE(s): CVE-2022-29885
Type:
security
Severity:
Important
Release date:
2023-07-10 17:27:50 UTC
Description:
* SECURITY UPDATE: EncryptInterceptor only provides partial protection on untrusted network - debian/patches/CVE-2022-29885.patch: Update the documentation to state that the EncryptInterceptor does not provide sufficient protection to run Tomcat clustering over an untrusted network. - CVE-2022-29885
Updated packages:
  • libtomcat9-embed-java_9.0.16-3ubuntu0.18.04.2+tuxcare.els2_all.deb
    sha:fa6c7d46026f048f707f6aaf7608911f4a1e675e
  • libtomcat9-java_9.0.16-3ubuntu0.18.04.2+tuxcare.els2_all.deb
    sha:bd88fcecef21a33ade7a2621a1988f6d967b90a7
  • tomcat9_9.0.16-3ubuntu0.18.04.2+tuxcare.els2_all.deb
    sha:69b824475180a5a0a1fad9376d89d9fff320bf77
  • tomcat9-admin_9.0.16-3ubuntu0.18.04.2+tuxcare.els2_all.deb
    sha:47f097721a350892e54832c39a2b542b016cb47e
  • tomcat9-common_9.0.16-3ubuntu0.18.04.2+tuxcare.els2_all.deb
    sha:8e50d70dde46d6b5eb016207654824e27d3c7c98
  • tomcat9-docs_9.0.16-3ubuntu0.18.04.2+tuxcare.els2_all.deb
    sha:850e837d3fd3568717328548a28b3decdb4dde89
  • tomcat9-examples_9.0.16-3ubuntu0.18.04.2+tuxcare.els2_all.deb
    sha:7c6075e64cf498cc803c6c1c0d096c005ea05a50
  • tomcat9-user_9.0.16-3ubuntu0.18.04.2+tuxcare.els2_all.deb
    sha:c8250d8f2349f086d13e5ac832ec62815440a96e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.