- 发布日期2020-10-21
- 感知时间2020-10-21
- 漏洞类型安全更新
- 风险等级未知
- 更新版本未知
- 情报贡献TSRC
USN-4596-1: Tomcat vulnerabilities
tomcat9 vulnerabilities<br/>A security issue affects these releases of Ubuntu and its derivatives:<br/>Ubuntu 20.04 LTS<br/>Summary<br/>Several security issues were fixed in Tomcat.<br/>Software Description<br/>tomcat9 - Apache Tomcat 9 - Servlet and JSP engine<br/>Details<br/>It was discovered that Tomcat did not properly manage HTTP/2 streams. An attacker could possibly use this to cause Tomcat to consume resources, resulting in a denial of service. (CVE-2020-11996)<br/>It was discovered that Tomcat did not properly release the HTTP/1.1 processor after the upgrade to HTTP/2. An attacker could possibly use this to generate an OutOfMemoryException, resulting in a denial of service. (CVE-2020-13934)<br/>It was discovered that Tomcat did not properly validate the payload length in a WebSocket frame. An attacker could possibly use this to trigger an infinite loop, resulting in a denial of service. (CVE-2020-13935)<br/>It was discovered that Tomcat did not properly deserialize untrusted data. An attacker could possibly use this issue to execute arbitrary code. (CVE-2020-9484)<br/>Update instructions<br/>The problem can be corrected by updating your system to the following package versions:<br/>Ubuntu 20.04 LTS<br/>libtomcat9-embed-java - 9.0.31-1ubuntu0.1<br/>libtomcat9-java - 9.0.31-1ubuntu0.1<br/>tomcat9 - 9.0.31-1ubuntu0.1<br/>tomcat9-common - 9.0.31-1ubuntu0.1<br/>To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.<br/>In general, a standard system update will make all the necessary changes.<br/>References<br/>CVE-2020-11996<br/>CVE-2020-13934<br/>CVE-2020-13935<br/>CVE-2020-9484<br/>]]>
Ubuntu是一个以桌面应用为主的Linux操作系统
<p><a target="_blank" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13935">CVE-2020-13935</a></p><p><a target="_blank" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13934">CVE-2020-13934</a></p><p><a target="_blank" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484">CVE-2020-9484</a></p><p><a target="_blank" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11996">CVE-2020-11996</a></p>
暂无
暂无
https://usn.ubuntu.com/4596-1/