[Git][security-tracker-team/security-tracker][master] Reserve DLA-4017-1 for tomcat9
Markus Koschany (@apo)
apo at debian.org
Thu Jan 16 23:15:31 GMT 2025
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker
Commits:
797908c9 by Markus Koschany at 2025-01-17T00:15:08+01:00
Reserve DLA-4017-1 for tomcat9
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -52338,7 +52338,6 @@ CVE-2024-38286 (Allocation of Resources Without Limits or Throttling vulnerabili
- tomcat10 10.1.25-1
[bookworm] - tomcat10 <postponed> (Minor issue, fixed along in next DSA)
- tomcat9 9.0.70-2
- [bullseye] - tomcat9 <postponed> (Minor issue, fixed along in next DSA)
NOTE: https://lists.apache.org/thread/wms60cvbsz3fpbz9psxtfx8r41jl6d4s
NOTE: https://github.com/apache/tomcat/commit/3344c17cef094da4bb616f4186ed32039627b543 (10.1.25)
NOTE: https://github.com/apache/tomcat/commit/76c5cce6f0bcef14b0c21c38910371ca7d322d13 (9.0.90)
@@ -102062,7 +102061,6 @@ CVE-2023-28743 (Improper input validation for some Intel NUC BIOS firmware befor
NOT-FOR-US: Intel
CVE-2024-21733 (Generation of Error Message Containing Sensitive Information vulnerabi ...)
- tomcat9 9.0.53-1
- [bullseye] - tomcat9 <postponed> (Minor issue, fix along in next update)
[buster] - tomcat9 <postponed> (Minor issue, fix along in next update)
NOTE: https://www.openwall.com/lists/oss-security/2024/01/19/2
NOTE: https://github.com/apache/tomcat/commit/86ccc43940861703c2be96a5f35384407522125a (9.0.44)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[17 Jan 2025] DLA-4017-1 tomcat9 - security update
+ {CVE-2024-21733 CVE-2024-38286 CVE-2024-50379 CVE-2024-52316 CVE-2024-56337}
+ [bullseye] - tomcat9 9.0.43-2~deb11u11
[16 Jan 2025] DLA-4016-1 ucf - security update
[bullseye] - ucf 3.0043+deb11u1
[14 Jan 2025] DLA-4015-1 rsync - security update
=====================================
data/dla-needed.txt
=====================================
@@ -253,11 +253,6 @@ tcpdf (Adrian Bunk)
NOTE: 20241205: Added by Front-Desk (santiago)
NOTE: 20241230: https://lists.debian.org/debian-lts/2024/12/msg00057.html (bunk)
--
-tomcat9
- NOTE: 20240908: Added by (apo)
- NOTE: 20240923: Still working on patch backport. (apo)
- NOTE: 20241010: Will release shortly after exim4 at the beginning of next week. (apo)
---
trafficserver (dleidert)
NOTE: 20241120: Added by Front-Desk (Beuc)
NOTE: 20241120: Upcoming DSA (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/797908c9d9beb1a2395b49725e45bc239da118a5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/797908c9d9beb1a2395b49725e45bc239da118a5
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250116/378e11f1/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list