[Git][security-tracker-team/security-tracker][master] dla: postpone tomcat9

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Tue May 6 16:31:36 BST 2025



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9cd4a203 by Sylvain Beucler at 2025-05-06T17:29:54+02:00
dla: postpone tomcat9

We issued DLA-4108-1 only last month.
None of the 2 new issues appear urgent.
When fixed in stable, this will be caught by lts-cve-triage.py.

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -2980,6 +2980,7 @@ CVE-2025-31651 (Improper Neutralization of Escape, Meta, or Control Sequences vu
 	- tomcat11 11.0.6-1
 	- tomcat10 10.1.40-1
 	- tomcat9 9.0.70-2
+	[bullseye] - tomcat9 <postponed> (Minor issue, unlikely access control bypass, fix along with next DLA)
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: Fixed by: https://github.com/apache/tomcat/commit/fbecc915a10c5a3d634c5e2c6ced4ff479ce9953 (11.0.6)
 	NOTE: Fixed by: https://github.com/apache/tomcat/commit/066bf6b6a15a4e7e0941d4acf096841165b97098 (10.1.40)
@@ -2989,6 +2990,7 @@ CVE-2025-31650 (Improper Input Validation vulnerability in Apache Tomcat. Incorr
 	- tomcat11 11.0.6-1
 	- tomcat10 10.1.40-1
 	- tomcat9 9.0.70-2
+	[bullseye] - tomcat9 <postponed> (Minor issue, DoS, fix along with next DLA)
 	NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
 	NOTE: https://lists.apache.org/thread/j6zzk0y3yym9pzfzkq5vcyxzz0yzh826
 	NOTE: Fixed by: https://github.com/apache/tomcat/commit/75554da2fc5574862510ae6f0d7b3d78937f1d40 (11.0.6)


=====================================
data/dla-needed.txt
=====================================
@@ -401,9 +401,6 @@ tcpdf
 thunderbird (lee)
   NOTE: 20250418: Added by Front-Desk (ta)
 --
-tomcat9
-  NOTE: 20250429: Added by Front-Desk (lamby)
---
 trafficserver
   NOTE: 20241120: Added by Front-Desk (Beuc)
   NOTE: 20241120: Upcoming DSA (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9cd4a203dff2f46cd7e941c72eada56ac3333f21

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9cd4a203dff2f46cd7e941c72eada56ac3333f21
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250506/0fde9738/attachment.htm>


More information about the debian-security-tracker-commits mailing list