Updated tomcat packages fix security vulnerabilities
Publication date: 29 Oct 2025Modification date: 29 Oct 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-55752 , CVE-2025-55754 , CVE-2025-61795
Description
Directory traversal via rewrite with possible RCE if PUT is enabled.
(CVE-2025-55752)
Console manipulation via escape sequences in log messages.
(CVE-2025-55754)
Delayed cleaning of multi-part upload temporary files may lead to DoS.
(CVE-2025-61795)
References
- https://bugs.mageia.org/show_bug.cgi?id=34699
- https://www.openwall.com/lists/oss-security/2025/10/27/4
- https://www.openwall.com/lists/oss-security/2025/10/27/5
- https://www.openwall.com/lists/oss-security/2025/10/27/6
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-55752
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-55754
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61795
SRPMS
9/core
- tomcat-9.0.111-1.mga9