Advisories ยป MGASA-2025-0250

Updated tomcat packages fix security vulnerabilities

Publication date: 29 Oct 2025
Modification date: 29 Oct 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-55752 , CVE-2025-55754 , CVE-2025-61795

Description

Directory traversal via rewrite with possible RCE if PUT is enabled.
(CVE-2025-55752)
Console manipulation via escape sequences in log messages.
(CVE-2025-55754)
Delayed cleaning of multi-part upload temporary files may lead to DoS.
(CVE-2025-61795)
                

References

SRPMS

9/core