-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4680-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 06, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : tomcat9 CVE ID : CVE-2019-10072 CVE-2019-12418 CVE-2019-17563 CVE-2019-17569 CVE-2020-1935 CVE-2020-1938 Several vulnerabilities were discovered in the Tomcat servlet and JSP engine, which could result in HTTP request smuggling, code execution in the AJP connector (disabled by default in Debian) or a man-in-the-middle attack against the JMX interface. For the stable distribution (buster), these problems have been fixed in version 9.0.31-1~deb10u1. The fix for CVE-2020-1938 may require configuration changes when Tomcat is used with the AJP connector, e.g. in combination with libapache-mod-jk. For instance the attribute "secretRequired" is set to true by default now. For affected setups it's recommended to review https://tomcat.apache.org/tomcat-9.0-doc/config/ajp.html before the deploying the update. We recommend that you upgrade your tomcat9 packages. For the detailed security status of tomcat9 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/tomcat9 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl6zJKQACgkQEMKTtsN8 TjYyjQ/+PcaMqPqvviDHl79uke1rIdFNyZ0bJU5prm9aQgv2/YF1AxlTE6Iim+yJ uvqTpLEWYF4eufOj9uh9XgBMvjfPcB6iPqQ3fot4kuIgZmwyX5yeMdEEPvAMOC2r a/+gFWkLtWNO4ppQeOppUhGgagmWtWLcVrDZX09JS+loLufqcNdGWFv8PIUH+jZO J9r93seU5mafKV7h7G3Z2gdAWIV2XRJVpk5x1w4O8VAft6aZ9Tn9VTV18MNJiy3H hS0kxempEUzSu/kQWUWjxICrhKH/WmAoFJJGUeKj5nj9AIf1m1aXPOppq4ww1DyX VU3htZ06YejVDKOtJ4cotNWVZU/HWSZXlHeKnzDFTfjjlhvW53wM5CfNuWqtNGHG jLN7qj3Y/kmhy55IxABqMSS9lpSZiGjjytOi4fKGKL3xryDl7NsIAUPmxm7YQQya +VBihzj0rXRYMPGctisBA71SkMML9fB+OzqmSAI7DAz+AxMotipsJGGCpiWfT8Ke 4opXXQe+NhVx2jCtjExI8bvM7mfvHE/N13VNpdxGwTvjYm5tFHKvNOg3X8QR01/a EC+5xiUJh3ilL3zCw7mP+3tv9p5TFuphA1hWJygudnZg4UtqjgBzuAtNkWUIt/xe JTtGcm/HQuYhsZbO3pqwo8pm92LeUfs7YFp2NPTU7SaYt3uWxKM= =WcA6 -----END PGP SIGNATURE-----