drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Preisgabe von Informationen in Tomcat (Aktualisierung)
| Name: |
Preisgabe von Informationen in Tomcat (Aktualisierung) |
|
| ID: |
USN-7525-2 |
|
| Distribution: |
Ubuntu |
|
| Plattformen: |
Ubuntu 24.04 LTS, Ubuntu 24.10, Ubuntu 25.04 |
|
| Datum: |
Di, 27. Mai 2025, 07:17 |
|
| Referenzen: |
https://www.cve.org/CVERecord?id=CVE-2025-24813 |
|
| Applikationen: |
Apache Tomcat |
|
| Update von: |
Preisgabe von Informationen in Tomcat |
|
Originalnachricht |
--===============0110286800748558037== Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="===============8691116117856772292=="
--===============8691116117856772292== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit
========================================================================== Ubuntu Security Notice USN-7525-2 May 26, 2025
Tomcat vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS
Summary:
Tomcat could expose sensitive files or run programs if it received specially crafted network traffic.
Software Description: - tomcat9: Apache Tomcat 9 - Servlet and JSP engine
Details:
USN-7525-1 fixed CVE-2025-24813 for tomcat9 in Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 18.04 LTS. This update fixes it for tomcat9 in Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.10. These versions include only the tomcat library (libtomcat9-java) and not the full tomcat server stack.
Original advisory details:
It was discovered that Apache Tomcat incorrectly implemented partial PUT functionality by replacing path separators with dots in temporary files. A remote attacker could possibly use this issue to access sensitive files, inject malicious content, or execute remote code.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 25.04 libtomcat9-java 9.0.70-2ubuntu1.25.04.1
Ubuntu 24.10 libtomcat9-java 9.0.70-2ubuntu1.24.10.1
Ubuntu 24.04 LTS libtomcat9-java 9.0.70-2ubuntu0.1+esm1 Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-7525-2 https://ubuntu.com/security/notices/USN-7525-2 CVE-2025-24813
Package Information: https://launchpad.net/ubuntu/+source/tomcat9/9.0.70-2ubuntu1.25.04.1 https://launchpad.net/ubuntu/+source/tomcat9/9.0.70-2ubuntu1.24.10.1
--===============8691116117856772292== Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmg1PvQACgkQcpJm3tlz hgE7MxAAoC6Wh3cQnomzYek6RgkkA0cExyq8va4w45lxDBHJ8kx1fNK6K+pa6xam lov1uO4/Y2tc4QbusIF5DdLQOtc8RR+29hPjM+xPVJkgoy74DmVJ95/vyqSG21I9 VBIbeP1QTudFdYSv/iHDxk8l8+17YpaHDjRZ/8YYCtTjX4YEqLbxmn/e4stw57bj 92BtS87PCBdQmYW9jclnPfQM4GtfBmo0b4rYLd1jLv5iV4rmDWE1AU05UooKb9gr qe9IwohHFFp4YnM9reLBHtCufBFhe0B6e1ViHUYFUTIymNTug/A7sDA4PLZJ59PB kLj1AB1ltvlQCHd0Uuc2cUunEvRRxbrq9ZN68UO7VLnAJggWScZbTFlH379eUGVv D3wjbJ/Aa5C3U33zc0FFqWzGpxs8zjWe8kNtMWMCTW4nG6K89hU3n1NIO1FnQ5pM tcdttXTfQJHCOBfG0luw7BBAPn3BZZIEGUdWw/DzZjpTz2fpviXs/ooA3DwIQh+M Zm0S/u9t0UEWT1zqy+nGaIBTQ0xTi5BBaSWZaPUyjjFF7wpTEWgnSRK9fkY6jlWN olLVYn3ePuk/huTD3t7eUbDTpaERIA/YkaRHuZZTEE0n/AVShB2UadrGyOzMR1b6 JL/w5uZnL5iFuAEuLFLfCBR3ghs/uHuI6KwkTcGlSaa41y9UGeY= =ZyrN -----END PGP SIGNATURE-----
--===============8691116117856772292==--
--===============0110286800748558037== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
--===============0110286800748558037==--
|
|
|
|