Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
9cd4a203 by Sylvain Beucler at 2025-05-06T17:29:54+02:00
dla: postpone tomcat9

We issued DLA-4108-1 only last month.
None of the 2 new issues appear urgent.
When fixed in stable, this will be caught by lts-cve-triage.py.

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -2980,6 +2980,7 @@ CVE-2025-31651 (Improper Neutralization of Escape, Meta, 
or Control Sequences vu
        - tomcat11 11.0.6-1
        - tomcat10 10.1.40-1
        - tomcat9 9.0.70-2
+       [bullseye] - tomcat9 <postponed> (Minor issue, unlikely access control 
bypass, fix along with next DLA)
        NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server 
stack, using that as the fixed version
        NOTE: Fixed by: 
https://github.com/apache/tomcat/commit/fbecc915a10c5a3d634c5e2c6ced4ff479ce9953
 (11.0.6)
        NOTE: Fixed by: 
https://github.com/apache/tomcat/commit/066bf6b6a15a4e7e0941d4acf096841165b97098
 (10.1.40)
@@ -2989,6 +2990,7 @@ CVE-2025-31650 (Improper Input Validation vulnerability 
in Apache Tomcat. Incorr
        - tomcat11 11.0.6-1
        - tomcat10 10.1.40-1
        - tomcat9 9.0.70-2
+       [bullseye] - tomcat9 <postponed> (Minor issue, DoS, fix along with next 
DLA)
        NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server 
stack, using that as the fixed version
        NOTE: https://lists.apache.org/thread/j6zzk0y3yym9pzfzkq5vcyxzz0yzh826
        NOTE: Fixed by: 
https://github.com/apache/tomcat/commit/75554da2fc5574862510ae6f0d7b3d78937f1d40
 (11.0.6)


=====================================
data/dla-needed.txt
=====================================
@@ -401,9 +401,6 @@ tcpdf
 thunderbird (lee)
   NOTE: 20250418: Added by Front-Desk (ta)
 --
-tomcat9
-  NOTE: 20250429: Added by Front-Desk (lamby)
---
 trafficserver
   NOTE: 20241120: Added by Front-Desk (Beuc)
   NOTE: 20241120: Upcoming DSA (Beuc/front-desk)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9cd4a203dff2f46cd7e941c72eada56ac3333f21

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9cd4a203dff2f46cd7e941c72eada56ac3333f21
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to