Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in Tomcat (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in Tomcat (Aktualisierung)
ID: USN-7525-2
Distribution: Ubuntu
Plattformen: Ubuntu 24.04 LTS, Ubuntu 24.10, Ubuntu 25.04
Datum: Di, 27. Mai 2025, 07:17
Referenzen: https://www.cve.org/CVERecord?id=CVE-2025-24813
Applikationen: Apache Tomcat
Update von: Preisgabe von Informationen in Tomcat

Originalnachricht

--===============0110286800748558037==
Content-Type: multipart/signed; micalg="pgp-sha256";
protocol="application/pgp-signature";
boundary="===============8691116117856772292=="

--===============8691116117856772292==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit

==========================================================================
Ubuntu Security Notice USN-7525-2
May 26, 2025

Tomcat vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 25.04
- Ubuntu 24.10
- Ubuntu 24.04 LTS

Summary:

Tomcat could expose sensitive files or run programs if it received
specially crafted network traffic.

Software Description:
- tomcat9: Apache Tomcat 9 - Servlet and JSP engine

Details:

USN-7525-1 fixed CVE-2025-24813 for tomcat9 in Ubuntu 22.04 LTS,
Ubuntu 20.04 LTS, and Ubuntu 18.04 LTS. This update fixes it for
tomcat9 in Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.10.
These versions include only the tomcat library (libtomcat9-java)
and not the full tomcat server stack.

Original advisory details:

It was discovered that Apache Tomcat incorrectly implemented partial
PUT functionality by replacing path separators with dots in temporary
files. A remote attacker could possibly use this issue to access
sensitive files, inject malicious content, or execute remote code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.04
libtomcat9-java 9.0.70-2ubuntu1.25.04.1

Ubuntu 24.10
libtomcat9-java 9.0.70-2ubuntu1.24.10.1

Ubuntu 24.04 LTS
libtomcat9-java 9.0.70-2ubuntu0.1+esm1
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7525-2
https://ubuntu.com/security/notices/USN-7525-2
CVE-2025-24813

Package Information:
https://launchpad.net/ubuntu/+source/tomcat9/9.0.70-2ubuntu1.25.04.1
https://launchpad.net/ubuntu/+source/tomcat9/9.0.70-2ubuntu1.24.10.1

--===============8691116117856772292==
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmg1PvQACgkQcpJm3tlz
hgE7MxAAoC6Wh3cQnomzYek6RgkkA0cExyq8va4w45lxDBHJ8kx1fNK6K+pa6xam
lov1uO4/Y2tc4QbusIF5DdLQOtc8RR+29hPjM+xPVJkgoy74DmVJ95/vyqSG21I9
VBIbeP1QTudFdYSv/iHDxk8l8+17YpaHDjRZ/8YYCtTjX4YEqLbxmn/e4stw57bj
92BtS87PCBdQmYW9jclnPfQM4GtfBmo0b4rYLd1jLv5iV4rmDWE1AU05UooKb9gr
qe9IwohHFFp4YnM9reLBHtCufBFhe0B6e1ViHUYFUTIymNTug/A7sDA4PLZJ59PB
kLj1AB1ltvlQCHd0Uuc2cUunEvRRxbrq9ZN68UO7VLnAJggWScZbTFlH379eUGVv
D3wjbJ/Aa5C3U33zc0FFqWzGpxs8zjWe8kNtMWMCTW4nG6K89hU3n1NIO1FnQ5pM
tcdttXTfQJHCOBfG0luw7BBAPn3BZZIEGUdWw/DzZjpTz2fpviXs/ooA3DwIQh+M
Zm0S/u9t0UEWT1zqy+nGaIBTQ0xTi5BBaSWZaPUyjjFF7wpTEWgnSRK9fkY6jlWN
olLVYn3ePuk/huTD3t7eUbDTpaERIA/YkaRHuZZTEE0n/AVShB2UadrGyOzMR1b6
JL/w5uZnL5iFuAEuLFLfCBR3ghs/uHuI6KwkTcGlSaa41y9UGeY=
=ZyrN
-----END PGP SIGNATURE-----

--===============8691116117856772292==--


--===============0110286800748558037==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline


--===============0110286800748558037==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung