From a4afff138b8507c9b0b4fdbebda4c8d1935d6238 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sun, 21 Aug 2022 01:35:21 +0000 Subject: [ GLSA 202208-34 ] Apache Tomcat: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/773571 Bug: https://bugs.gentoo.org/801916 Bug: https://bugs.gentoo.org/818160 Bug: https://bugs.gentoo.org/855971 Signed-off-by: GLSAMaker Signed-off-by: John Helmert III --- glsa-202208-34.xml | 69 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 69 insertions(+) create mode 100644 glsa-202208-34.xml diff --git a/glsa-202208-34.xml b/glsa-202208-34.xml new file mode 100644 index 0000000..934c979 --- /dev/null +++ b/glsa-202208-34.xml @@ -0,0 +1,69 @@ + + + + Apache Tomcat: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in Apache Tomcat, the worst of which could result in denial of service. + tomcat + 2022-08-21 + 2022-08-21 + 773571 + 801916 + 818160 + 855971 + remote + + + 10.0.23 + 9.0.65 + 8.5.82 + 10.0.23 + 9.0.65 + 8.5.82 + + + +

Apache Tomcat is a Servlet-3.0/JSP-2.2 Container.

+
+ +

Multiple vulnerabilities have been discovered in Apache Tomcat. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Apache Tomcat 10.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-servers/tomcat-10.0.23:10" + + +

All Apache Tomcat 9.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-servers/tomcat-9.0.65:9" + + +

All Apache Tomcat 8.5.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-servers/tomcat-8.5.82:8.5" + +
+ + CVE-2021-25122 + CVE-2021-25329 + CVE-2021-30639 + CVE-2021-30640 + CVE-2021-33037 + CVE-2021-42340 + CVE-2022-34305 + + ajak + ajak +
\ No newline at end of file -- cgit v1.2.3-18-g5258