USN-7032-1: Tomcat vulnerability
Published Sep 24, 2024
·Updated
It was discovered that Tomcat incorrectly handled HTTP trailer headers. A remote attacker could possibly use this issue to perform HTTP request smuggling.
Affected Software
18 affected componentsFixes available
All of the following
ubuntu/libtomcat9-java<9.0.70-2ubuntu0.1
9.0.70-2ubuntu0.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/libtomcat9-embed-java<9.0.58-1ubuntu0.1+esm3
9.0.58-1ubuntu0.1+esm3
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libtomcat9-java<9.0.58-1ubuntu0.1+esm3
9.0.58-1ubuntu0.1+esm3
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libtomcat9-embed-java<9.0.31-1ubuntu0.7
9.0.31-1ubuntu0.7
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libtomcat9-java<9.0.31-1ubuntu0.7
9.0.31-1ubuntu0.7
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libtomcat8-embed-java<8.5.39-1ubuntu1~18.04.3+esm3
8.5.39-1ubuntu1~18.04.3+esm3
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libtomcat8-java<8.5.39-1ubuntu1~18.04.3+esm3
8.5.39-1ubuntu1~18.04.3+esm3
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libtomcat9-embed-java<9.0.16-3ubuntu0.18.04.2+esm3
9.0.16-3ubuntu0.18.04.2+esm3
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libtomcat9-java<9.0.16-3ubuntu0.18.04.2+esm3
9.0.16-3ubuntu0.18.04.2+esm3
Ubuntu Ubuntu=18.04
Event History
Sep 24, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7032-1?
The severity of USN-7032-1 is high due to the potential for HTTP request smuggling.
2
How do I fix USN-7032-1?
To fix USN-7032-1, upgrade to the fixed package version specified for your affected Ubuntu version.
3
Which versions are affected by USN-7032-1?
USN-7032-1 affects specific versions of libtomcat9-java and libtomcat9-embed-java for Ubuntu 20.04, 22.04, and 24.04.
4
What was the cause of the vulnerability in USN-7032-1?
The vulnerability in USN-7032-1 was caused by Tomcat incorrectly handling HTTP trailer headers.
5
Can USN-7032-1 be exploited remotely?
Yes, a remote attacker could exploit USN-7032-1 to perform HTTP request smuggling.