Release Info

Advisory: CLSA-2023:1687469807

OS: Ubuntu 18.04 ELS

Public date: 2023-06-22 17:36:49

Project: tomcat8

Version: 8.5.39-1ubuntu1~18.04.3+tuxcare.els2

Errata link: https://errata.tuxcare.com/els_os/ubuntu18.04els/CLSA-2023-1687469807.html

Changelog

* SECURITY UPDATE: Apache Tomcat h2c request mix-up - debian/patches/CVE-2021-25122.patch: Simplify the code and fix an edge case for BZ 64830 - CVE-2021-25122 * SECURITY UPDATE: Denial of Service for NIO+OpenSSL or NIO2+OpenSSL TLS configurations - debian/patches/CVE-2021-41079.patch: Improve robustness - CVE-2021-41079

Update

Update command: apt-get update apt-get --only-upgrade install tomcat8*

Packages list

libtomcat8-embed-java_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb libtomcat8-java_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb tomcat8_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb tomcat8-admin_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb tomcat8-common_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb tomcat8-docs_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb tomcat8-examples_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb tomcat8-user_8.5.39-1ubuntu1~18.04.3+tuxcare.els2_all.deb

CVEs

CVE-2021-25122
CVE-2021-41079