[Git][security-tracker-team/security-tracker][master] Reserve DLA-4017-1 for tomcat9

Markus Koschany (@apo) apo at debian.org
Thu Jan 16 23:15:31 GMT 2025



Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker


Commits:
797908c9 by Markus Koschany at 2025-01-17T00:15:08+01:00
Reserve DLA-4017-1 for tomcat9

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -52338,7 +52338,6 @@ CVE-2024-38286 (Allocation of Resources Without Limits or Throttling vulnerabili
 	- tomcat10 10.1.25-1
 	[bookworm] - tomcat10 <postponed> (Minor issue, fixed along in next DSA)
 	- tomcat9 9.0.70-2
-	[bullseye] - tomcat9 <postponed> (Minor issue, fixed along in next DSA)
 	NOTE: https://lists.apache.org/thread/wms60cvbsz3fpbz9psxtfx8r41jl6d4s
 	NOTE: https://github.com/apache/tomcat/commit/3344c17cef094da4bb616f4186ed32039627b543 (10.1.25)
 	NOTE: https://github.com/apache/tomcat/commit/76c5cce6f0bcef14b0c21c38910371ca7d322d13 (9.0.90)
@@ -102062,7 +102061,6 @@ CVE-2023-28743 (Improper input validation for some Intel NUC BIOS firmware befor
 	NOT-FOR-US: Intel
 CVE-2024-21733 (Generation of Error Message Containing Sensitive Information vulnerabi ...)
 	- tomcat9 9.0.53-1
-	[bullseye] - tomcat9 <postponed> (Minor issue, fix along in next update)
 	[buster] - tomcat9 <postponed> (Minor issue, fix along in next update)
 	NOTE: https://www.openwall.com/lists/oss-security/2024/01/19/2
 	NOTE: https://github.com/apache/tomcat/commit/86ccc43940861703c2be96a5f35384407522125a (9.0.44)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[17 Jan 2025] DLA-4017-1 tomcat9 - security update
+	{CVE-2024-21733 CVE-2024-38286 CVE-2024-50379 CVE-2024-52316 CVE-2024-56337}
+	[bullseye] - tomcat9 9.0.43-2~deb11u11
 [16 Jan 2025] DLA-4016-1 ucf - security update
 	[bullseye] - ucf 3.0043+deb11u1
 [14 Jan 2025] DLA-4015-1 rsync - security update


=====================================
data/dla-needed.txt
=====================================
@@ -253,11 +253,6 @@ tcpdf (Adrian Bunk)
   NOTE: 20241205: Added by Front-Desk (santiago)
   NOTE: 20241230: https://lists.debian.org/debian-lts/2024/12/msg00057.html (bunk)
 --
-tomcat9
-  NOTE: 20240908: Added by (apo)
-  NOTE: 20240923: Still working on patch backport. (apo)
-  NOTE: 20241010: Will release shortly after exim4 at the beginning of next week. (apo)
---
 trafficserver (dleidert)
   NOTE: 20241120: Added by Front-Desk (Beuc)
   NOTE: 20241120: Upcoming DSA (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/797908c9d9beb1a2395b49725e45bc239da118a5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/797908c9d9beb1a2395b49725e45bc239da118a5
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250116/378e11f1/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list