it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Moritz Muehlenhoff <jmm AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 6005-1] jetty9 security update
- Date: Fri, 19 Sep 2025 18:34:00 +0000
- Authentication-results: lists.piratenpartei.de; dkim=none; dmarc=none; spf=none (lists.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 2001:41b8:202:deb:216:36ff:fe40:4002) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"
- List-archive: https://lists.debian.org/msgid-search/aM2iGLmjDK_8td5U AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=2y7pwkVg/BV6lBhlFaUvBbr+jO9XGL0oLxUXsqu24Z4=; b=J3 uvOZYCeeUA7KvSU3Cu1GPEuc9QGhyxbQB7cFHFB0vjUiHsbyqEn0BPie4JA5ztDmFFzSsZ5k9nVTK F7ThYg+HoK4J06/almtFIZqGpQMvkaEk8gOD2kw2q6L+RzTUEUKsn5dSP/Nn9mAhjzl5Sjj1GV+8i XvsyXJfdQvfhaWM3nX4L/bJzv/GiiuDb25KQfbSimDPT5KhGRqBSzRbykicJQb4Q1FGVwzaDFRbgF qp8X+muvFbe5oBqB+94Dnz7sxORVDHRb9/sQlhf8SMj2OQ985s1Wm/lQk8PFeGYbWaxlz8fq1zM9w t4KXctdafH9iPbbNhC/R9noAwODqevoQ==;
- Old-return-path: <jmm AT seger.debian.org>
- Priority: urgent
- Resent-date: Fri, 19 Sep 2025 18:34:27 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <Eq1wgejMyFH.A.kkeI.zIazoB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6005-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
September 19, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : jetty9
CVE ID : CVE-2025-5115
This update for Jetty, a Java servlet engine and web server, addresses a
protocol-level vulnerability in HTTP/2 support also referred to as
"MadeYouReset".
For the oldstable distribution (bookworm), this problem has been fixed
in version 9.4.57-1.1~deb12u1.
For the stable distribution (trixie), this problem has been fixed in
version 9.4.57-1.1~deb13u1.
We recommend that you upgrade your jetty9 packages.
For the detailed security status of jetty9 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/jetty9
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmjNoSQACgkQEMKTtsN8
TjaidQ//ZJ/M3/JQ5/Pj4jN1bF+JnX1DKY/t44ywP5cmaSMBU1nqnYmtIJXmnuq5
qRoPGb4Ado/8K7QLG1K24U2DRLm8andVeHEyS7xb4Ep4GMeYLCOwOAmf04T9gyvK
iUv/41DfS8blVSO4k42cilg4itNnJuY9ROdGL8xyKIIts2Es7hKa5IyAtASCNfoL
A93l1fh+7llP2lLRPiRTGf9JdsHDSeLnjwvtDWh9t01N6Xcsdf/EdXPy9ePQspue
Hi57B/i79JyOwJdzVOZIu566xtZddpHfpzKcSX8v1O+zNqulGu7b8FFiqTGLS3ke
reAk0dLZ2k5EQv/82D8U0ejcUrQJcUMqIGN6ln1tZmwkbQUeS/wZuBrA+kHttu2x
sn70s+sjO5iZePp3gjryNuskkktGT3nxBik3I1K0x60tsxAIoFwuYyzEpAdvOS50
+7Wwxx4dDB6ESYOi1M1NojYpSqt9xJl0pMe7cBGJwBYJzk+QG01fUZHmKyTX5rK/
WQjkOFfOCGMqywS7DL2zLgr1M8khzt3lbvKQP/X3+MBVkIwX4Pxbj0SV1oW0y++4
jYNfkJK2XB/0UpPMeK7EaEhMADy+yHMHiXYamLkKFigZsN5LHtzyIQyUxjOekeex
CSyf8gI0lk1XSYmw4RGB1jXQnwqhw5FwpzUi3DkmTRB1T+p6718=
=0Fal
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 6005-1] jetty9 security update, Moritz Muehlenhoff, 19.09.2025
Archiv bereitgestellt durch MHonArc 2.6.19+.