[CLSA-2024:1707420277] Fix CVE(s): CVE-2023-46589
Type:
security
Severity:
Important
Release date:
2024-02-08 19:24:40 UTC
Description:
* SECURITY UPDATE: Incorrect parsing of HTTP trailer headers - debian/patches/CVE-2023-46589.patch: Ensure IOException on request read always triggers error handling - CVE-2023-46589 * Internal tests: - debian/patches/0100-stop-testing-if-a-failure-occurs.patch: Stop testing if a failure occurs - debian/patches/0101-skipping-tests-incompatible-with-firewall.patch: Skipping tests incompatible with the firewall settings of the build system - debian/test_certs/*, debian/source/include-binaries, debian/rules: Update the keystore files and certificates from the upstream branch 9.0.x to fix internal tests
Updated packages:
  • libtomcat9-embed-java_9.0.16-3ubuntu0.18.04.2+tuxcare.els4_all.deb
    sha:f841f1b5918f56aea65d19b6ae0d4caf7a9bd248
  • libtomcat9-java_9.0.16-3ubuntu0.18.04.2+tuxcare.els4_all.deb
    sha:16d8718e1bc4b9d4faa579a242e6c04945bc69a0
  • tomcat9_9.0.16-3ubuntu0.18.04.2+tuxcare.els4_all.deb
    sha:5f9152121f78e376535b2d5d62b6b2c2b505c630
  • tomcat9-admin_9.0.16-3ubuntu0.18.04.2+tuxcare.els4_all.deb
    sha:f6412f40d46eb24d5bfe0489d1799000b47069fe
  • tomcat9-common_9.0.16-3ubuntu0.18.04.2+tuxcare.els4_all.deb
    sha:34f5637d2d3cec09b9cf385ac01b505196183776
  • tomcat9-docs_9.0.16-3ubuntu0.18.04.2+tuxcare.els4_all.deb
    sha:8aa78717e7f36dea95f9afa3da445cc8a82a54cd
  • tomcat9-examples_9.0.16-3ubuntu0.18.04.2+tuxcare.els4_all.deb
    sha:3eeddcf7e025f17eab724d0adcf627e742e07a7b
  • tomcat9-user_9.0.16-3ubuntu0.18.04.2+tuxcare.els4_all.deb
    sha:c968ddc5a981e99162296be28b3dc394a049fa81
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.