tomcat10_10.1.6-1+deb12u1_source.changes ACCEPTED into proposed-updates->stable-new

Debian FTP Masters ftpmaster at ftp-master.debian.org
Tue Oct 10 23:20:30 BST 2023


Thank you for your contribution to Debian.

Mapping stable-security to proposed-updates.

Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 10 Oct 2023 18:33:08 +0200
Source: tomcat10
Architecture: source
Version: 10.1.6-1+deb12u1
Distribution: bookworm-security
Urgency: high
Maintainer: Debian Java Maintainers <pkg-java-maintainers at lists.alioth.debian.org>
Changed-By: Emmanuel Bourg <ebourg at apache.org>
Changes:
 tomcat10 (10.1.6-1+deb12u1) bookworm-security; urgency=high
 .
   * Fix CVE-2023-45648: Request smuggling. Tomcat did not correctly parse HTTP
     trailer headers. A specially crafted, invalid trailer header could cause
     Tomcat to treat a single request as multiple requests leading to the
     possibility of request smuggling when behind a reverse proxy.
   * Fix CVE-2023-44487: DoS caused by HTTP/2 frame overhead (Rapid Reset Attack)
   * Fix CVE-2023-42795: Information Disclosure. When recycling various internal
     objects, including the request and the response, prior to re-use by the next
     request/response, an error could cause Tomcat to skip some parts of the
     recycling process leading to information leaking from the current
     request/response to the next.
   * Fix CVE-2023-41080: Open redirect. If the ROOT (default) web application
     is configured to use FORM authentication then it is possible that a
     specially crafted URL could be used to trigger a redirect to an URL of
     the attackers choice.
   * Fix CVE-2023-28709: Denial of Service. If non-default HTTP connector
     settings were used such that the maxParameterCount could be reached using
     query string parameters and a request was submitted that supplied exactly
     maxParameterCount parameters in the query string, the limit for uploaded
     request parts could be bypassed with the potential for a denial of service
     to occur.
Checksums-Sha1:
 138fb74b250c598e3971372f1ee9aa92e8a56e72 2867 tomcat10_10.1.6-1+deb12u1.dsc
 b7ab68fccfd40b2665f1d2268e7a87f46968a5a4 3940916 tomcat10_10.1.6.orig.tar.xz
 b96e271b0c49eb6806dda4f4ba9adc5d49a58af1 43556 tomcat10_10.1.6-1+deb12u1.debian.tar.xz
 cf556a11a0b40056d5172978aebcb24b92d54423 15832 tomcat10_10.1.6-1+deb12u1_source.buildinfo
Checksums-Sha256:
 f3027eef47e9b5157078e245cfb5f693685a11e724b8adfdc5a01607b1bb80c1 2867 tomcat10_10.1.6-1+deb12u1.dsc
 9626aab2e70dd019a46a92eea2e7039a141ffc8611b8e873d1d0f0ae7f0b74f5 3940916 tomcat10_10.1.6.orig.tar.xz
 5da8671a3ede24b629dcbc2b28f7b45712abc153d9e05247cf1a1856f1449339 43556 tomcat10_10.1.6-1+deb12u1.debian.tar.xz
 628c95f96c9642856e3c9301010f5cca7740e78ee9306e150fc1206dc56d323e 15832 tomcat10_10.1.6-1+deb12u1_source.buildinfo
Files:
 10e1c5a7febb58d69afca1cf18a58024 2867 java optional tomcat10_10.1.6-1+deb12u1.dsc
 6fbf0c7655c053381b31933436b33441 3940916 java optional tomcat10_10.1.6.orig.tar.xz
 32dd1710c356a759b9c53cb10cee7aa7 43556 java optional tomcat10_10.1.6-1+deb12u1.debian.tar.xz
 721f70afa63afcc49c7f0feb14a5f20c 15832 java optional tomcat10_10.1.6-1+deb12u1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJGBAEBCgAwFiEEuM5N4hCA3PkD4WxA9RPEGeS50KwFAmUllBgSHGVib3VyZ0Bh
cGFjaGUub3JnAAoJEPUTxBnkudCsimUQAIBwr9SPkCegvPfBvr7/BiXPkW00Ldvw
0UgzhLBSd3EKmf4lX44tLRIIh3PhkNIFKzL/VzFATc0lVUhppR0EhTyn0IACtu5A
BH2eR1qoMO53zsYDen7iJucq1CJmSnE30Dr1vr5ZEAmgGt5QRupBHtDXY7vTTGaM
jq8//i37QYnNCaO6ehcNe+9rBbTeEgbT4MaxMiwIZMOuS/gqfADG2e2HPdNYjGqv
w0dVgqQP/PcZSGaZWXASeGi+c0Y6yye9x3rU/Zh//xlz3Sg5d0/rNbUh4gqytOnp
K8KHuvukbxWGzr1/s4MFysK01o6lsIpagdwyBdkfBr55RV2EAIlL0C0ZikE2dvbw
R6rkMg4u0SWa8XuUj8xEwwHORBO3/GxdMG9t0vM5aN6i390fMkVnHOIIpXOBcWMN
fV9d++yQlrbM/GlmY+0y5K1BJrhctMOs8Wfo8lkoQle6nG8DEnMfnRa1fgL42H3x
N8VdZDQLD4hTpt3YQVv/kQAcqPwlJ1QS5EcNd12MCCBbNSq6qO9oLJ7FWXAVEyYG
4BfIMWBPRsA2ETm7vmFTCKy2Lcb3HJraT7ect5+a3dzlq/9XRpz0c4sJN4uwKqY5
B0Qo+8yTVCN/mVl/cS5JxRG+fyiwcW9g/HietF8PlQUeRlk4vvbY2Dg2IXk37Qot
j24LT9HVMO2d
=QCBA
-----END PGP SIGNATURE-----




More information about the pkg-java-maintainers mailing list