USN-7410-1: Tomcat vulnerability
Published Apr 7, 2025
·Updated
It was discovered that Tomcat incorrectly handled request cancellation. A remote attacker could possibly use this issue to cause tomcat9 to consume resources, leading to a denial of service.
Affected Software
6 affected componentsFixes available
All of the following
ubuntu/tomcat9-common<9.0.58-1ubuntu0.2
9.0.58-1ubuntu0.2
Ubuntu Ubuntu=22.04
All of the following
ubuntu/tomcat9-common<9.0.31-1ubuntu0.9
9.0.31-1ubuntu0.9
Ubuntu Ubuntu=20.04
All of the following
ubuntu/tomcat9-common<9.0.16-3ubuntu0.18.04.2+esm5
9.0.16-3ubuntu0.18.04.2+esm5
Ubuntu Ubuntu=18.04
Event History
Apr 7, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7410-1?
The severity of USN-7410-1 is classified as a denial of service vulnerability.
2
How do I fix USN-7410-1?
To resolve USN-7410-1, upgrade tomcat9-common to the fixed version for your respective Ubuntu distribution.
3
Which versions of tomcat9 are affected by USN-7410-1?
USN-7410-1 affects tomcat9 versions prior to 9.0.58-1ubuntu0.2, 9.0.31-1ubuntu0.9, and 9.0.16-3ubuntu0.18.04.2+esm5.
4
What impact does USN-7410-1 have on my system?
USN-7410-1 can lead to resource exhaustion on the Tomcat server, resulting in a denial of service.
5
Is there any workaround for USN-7410-1?
There are no recommended workarounds for USN-7410-1; updating to the latest package version is advised.