Release Info

Advisory: CLSA-2023:1689009963

OS: Ubuntu 18.04 ELS

Public date: 2023-07-10 13:26:05

Project: tomcat8

Version: 8.5.39-1ubuntu1~18.04.3+tuxcare.els3

Errata link: https://errata.cloudlinux.com/ubuntu18-els/CLSA-2023-1689009963.html

Changelog

* SECURITY UPDATE: EncryptInterceptor only provides partial protection on untrusted network - debian/patches/CVE-2022-29885.patch: Update the documentation to state that the EncryptInterceptor does not provide sufficient protection to run Tomcat clustering over an untrusted network. - CVE-2022-29885

Update

Update command: apt-get update apt-get --only-upgrade install tomcat8*

Packages list

libtomcat8-embed-java_8.5.39-1ubuntu1~18.04.3+tuxcare.els3_all.deb libtomcat8-java_8.5.39-1ubuntu1~18.04.3+tuxcare.els3_all.deb tomcat8_8.5.39-1ubuntu1~18.04.3+tuxcare.els3_all.deb tomcat8-admin_8.5.39-1ubuntu1~18.04.3+tuxcare.els3_all.deb tomcat8-common_8.5.39-1ubuntu1~18.04.3+tuxcare.els3_all.deb tomcat8-docs_8.5.39-1ubuntu1~18.04.3+tuxcare.els3_all.deb tomcat8-examples_8.5.39-1ubuntu1~18.04.3+tuxcare.els3_all.deb tomcat8-user_8.5.39-1ubuntu1~18.04.3+tuxcare.els3_all.deb

CVEs

CVE-2022-29885