Advisories ยป MGASA-2024-0267

Updated tomcat packages fix security vulnerability

Publication date: 15 Jul 2024
Modification date: 15 Jul 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-34750

Description

Improper Handling of Exceptional Conditions, Uncontrolled Resource
Consumption vulnerability in Apache Tomcat. When processing an HTTP/2
stream, Tomcat did not handle some cases of excessive HTTP headers
correctly. This led to a miscounting of active HTTP/2 streams which in
turn led to the use of an incorrect infinite timeout which allowed
connections to remain open which should have been closed.
(CVE-2024-34750)
                

References

SRPMS

9/core