tomcat-9.0.87-1.el8_10.1.ML.1

エラータID: AXSA:2024-8475:09

Release date: 
Thursday, June 27, 2024 - 15:13
Subject: 
tomcat-9.0.87-1.el8_10.1.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.

Security Fix(es):

* Apache Tomcat: HTTP/2 header handling DoS (CVE-2024-24549)
* Apache Tomcat: WebSocket DoS with incomplete closing handshake (CVE-2024-23672)

Bug Fix(es):

* Rebase tomcat to version 9.0.87 (JIRA:RHEL-35813)
* Amend tomcat package's changelog so that fixed CVEs are mentioned explicitly (JIRA:RHEL-38548)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-23672
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
CVE-2024-24549
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. tomcat-9.0.87-1.el8_10.1.ML.1.src.rpm
    MD5: ac4d6430691f8bd3f3e51434aa0dcdb4
    SHA-256: 2a647533e2aced6453362e8bf2e7f8c0cfe6b75eae138eaadff6f2bf66342693
    Size: 15.10 MB

Asianux Server 8 for x86_64
  1. tomcat-9.0.87-1.el8_10.1.ML.1.noarch.rpm
    MD5: 93513171372fa4d272c14f3d3895bd23
    SHA-256: 809ceb0a7c16b0e13f4b28ecd3d77e63ec3bb5452dd4ade1bd2014d43b81c457
    Size: 91.72 kB
  2. tomcat-admin-webapps-9.0.87-1.el8_10.1.ML.1.noarch.rpm
    MD5: b2e19d885b06418de6387f456392edb8
    SHA-256: ae9b17d872671f4833f3600a12a6a89f4b4c7c70deabee02051f4b02c713b3c9
    Size: 72.66 kB
  3. tomcat-docs-webapp-9.0.87-1.el8_10.1.ML.1.noarch.rpm
    MD5: 797e4b8c0cba021148a607be40f8b3aa
    SHA-256: e30bcd8ffc4342f6127f5a5a18819c036ec77b71aedbb12b79439f4a838eba98
    Size: 753.64 kB
  4. tomcat-el-3.0-api-9.0.87-1.el8_10.1.ML.1.noarch.rpm
    MD5: 0faf108b871a897ec9594e1c7b784a22
    SHA-256: bfe2120c3a0735877c31e2cd12c9f959bd6ce2e8e800fc5915cb6c074fbf3d81
    Size: 105.68 kB
  5. tomcat-jsp-2.3-api-9.0.87-1.el8_10.1.ML.1.noarch.rpm
    MD5: 45cada731d81decc6736d5e3f56148a4
    SHA-256: d17b040e0f966016946575eb7aecd88fa4cb537388b7d36c37c9e88f563e4670
    Size: 71.58 kB
  6. tomcat-lib-9.0.87-1.el8_10.1.ML.1.noarch.rpm
    MD5: d3419ce022eefb6916f683614b108516
    SHA-256: 1771b9b393a98fe43063b6664e04b6c6e2033f3b5ccfd89d5237f542bb375de5
    Size: 6.04 MB
  7. tomcat-servlet-4.0-api-9.0.87-1.el8_10.1.ML.1.noarch.rpm
    MD5: 27f526b29cc681f3738b5d54fd3a3684
    SHA-256: 5e908787814a6fa56424e6e633aca4e0302293608b439822c993e0975009e6d5
    Size: 286.26 kB
  8. tomcat-webapps-9.0.87-1.el8_10.1.ML.1.noarch.rpm
    MD5: 16698819bdeaf2b666a67d44e4d852ba
    SHA-256: ba6d388bf73aaa39c73b1041f7c8e8410b246db72e69f3a52fccf4168fddcf48
    Size: 80.09 kB