Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5198-1] jetty9 security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5198-1] jetty9 security update


Chronologisch Thread  
  • From: Markus Koschany <apo AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5198-1] jetty9 security update
  • Date: Tue, 2 Aug 2022 11:01:19 +0000
  • Authentication-results: mail.piratenpartei.de; dkim=none; dmarc=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"
  • List-archive: https://lists.debian.org/msgid-search/20220802110119.GA14733 AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From: Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=IQu6xEm+aO6YnqreNyK6OXIlK2fcjjdW4DelH4fNYmo=; b=Wl cFpXJ+18ed3pbXr09URL5jHSWuxS4OgA1uzDEVNtk1XyQCRwwz2ouVwKZcEVqkwnge7ldiCgDp5R1 Vm14vkY2XSL4BNVGioFP00HCtJbi4nXA3Yqiq4jx2HFQg8brUXpjRRzEvR+vIuvkt8WrZEicyYqWe c88BLxJh7dglumgZeYbitWoz8NfWTPco+df27ChPiyHKgwEUj0721im/FMwxNYw88Km9RhQcbweJE hpPlo+HJTcgk2Bzamev5Ahxz3bsxZFLJvZPb4xgkEmDxTKjb3qc0Y2FljZSxUD/MR95DYKH405Jjw Gm7Ofb7hiR3Q5BKNX4PKkvoskapDKkhQ==;
  • Old-return-path: <apo AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Tue, 2 Aug 2022 11:18:10 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <79b0dJblzQI.A.eSF.yfQ6iB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5198-1 security AT debian.org
https://www.debian.org/security/ Markus Koschany
August 02, 2022 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : jetty9
CVE ID : CVE-2022-2047 CVE-2022-2048

Two security vulnerabilities were discovered in Jetty, a Java servlet engine
and webserver.

CVE-2022-2047

In Eclipse Jetty the parsing of the authority segment of an http scheme
URI, the Jetty HttpURI class improperly detects an invalid input as a
hostname. This can lead to failures in a Proxy scenario.

CVE-2022-2048

In Eclipse Jetty HTTP/2 server implementation, when encountering an
invalid
HTTP/2 request, the error handling has a bug that can wind up not properly
cleaning up the active connections and associated resources. This can lead
to a Denial of Service scenario where there are no enough resources left
to
process good requests.

For the stable distribution (bullseye), these problems have been fixed in
version 9.4.39-3+deb11u1.

We recommend that you upgrade your jetty9 packages.

For the detailed security status of jetty9 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/jetty9

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmLpA6BfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD
RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7
UeQ8pA/+KBrmSaq62Us9/7vxQtc1YHGerjyUU8q/WI0l1jvPsK9BtYeRCblSCBBP
XDlUX0uj5cQGZiOnKqb0KYBakfnp6aOVXYn6Ci/T7DRNyZqha3fbtc1pvq+O0t3B
ZmToDe33yezk52fdMRmp3Bc5BbWFe/vt3f3DPJnDJjT7PNtnK1TkPeTYdDGv84zU
SDTON00tEKz5S88bZYoMYkyBZfhDiWQP+YKCPWRDl8LoSZyJQDRv7pVS9X5hQ9bL
sATufdBUm7fdphrcJrIEpAySiBZCm/cmKvV1WFucuySXyGwm8RKZXj4piMp+MzuM
0V8hrYqfwwphuKmJEBjgCrv6AXwOKej+Fhw1iftasOOfju8vKvewAlPaSLgtYgWP
bjNr3TSN44SGqpTDHjlxyjvJ5vpovAib5MkYpdWWTX8iKUs24hPuU+XuiYfymFJn
L0vbj/Th1M42pLW3ZcfFhYKTPvSp2Fx+FvOpEyqM/vM15oY0+hvN8eQa6fYwDaqU
tr+iByTDpxgy8wHfY0+N/SLC888ILyaghB/N7okqkM3N+fJ1415lfMqFdxN52PY1
sxSamaXPkmzegO6FjxFbb8FCF97maoOyXhAhUZpkxf45WQrXdSMwcOeJOQFXcyh5
6gzdsxPMFOSVQ16RMYcK9HTqTjFLlcBLvW66ITGGl3T4f70hmM0=
=Xfx6
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5198-1] jetty9 security update, Markus Koschany, 02.08.2022

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang