Source: tomcat9 Version: 9.0.16-4 Severity: important Tags: security upstream Control: found -1 9.0.16-1
Hi, The following vulnerability was published for tomcat9. CVE-2019-10072[0]: | The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 | connection window exhaustion on write in Apache Tomcat versions | 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE | messages for the connection window (stream 0) clients were able to | cause server-side threads to block eventually leading to thread | exhaustion and a DoS. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2019-10072 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10072 Regards, Salvatore __ This is the maintainer address of Debian's Java team <https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-java-maintainers>. Please use [email protected] for discussions and questions.
