INFSA-2024:3666: Apache Tomcat security update

Information about definition

Identificator: INFSA-2024:3666

Type: security

Release date: 2024-08-27 10:04:37 UTC

Information about package

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.

Vulnerabilities description

  • CVE-2024-23672

    A denial of service (DoS) vulnerability present in the Apache Tomcat package arises from an incomplete cleanup process. Specifically, WebSocket clients can perpetuate WebSocket connections without proper termination, thereby causing a sustained drain on system resources. This vulnerability facilitates the exploitation of Apache Tomcat servers, leading to a scenario where excessive resource consumption occurs due to the prolonged existence of these open WebSocket connections. As a consequence, the server's performance may degrade significantly, resulting in potential service disruption or unresponsiveness.

  • CVE-2024-24549

    A vulnerability was found in the Tomcat package due to its handling of HTTP/2 requests. Specifically, when an HTTP/2 request surpasses the predetermined limits for headers configured within the server, the associated HTTP/2 stream isn't reset immediately. Instead, the reset action occurs only after all the headers within the request have been processed. This lapse in resetting the stream exposes the system to potential risks, as it allows malicious actors to exploit the delay in stream reset to carry out various attacks, such as header manipulation or resource exhaustion. Bug Fixes: * Rebase tomcat to version 9.0.87. * Amend tomcat package's changelog so that fixed CVEs are mentioned explicitly.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 7.5 no information
no information 7.5 no information
Critical, important, moderate, low

Updated packages