Name | CVE-2019-10072 |
Description | The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more) |
References | DSA-4680-1 |
Debian Bugs | 30873, 930872, 931131 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
tomcat9 (PTS) | buster | 9.0.31-1~deb10u6 | fixed |
buster (security) | 9.0.31-1~deb10u8 | fixed | |
bullseye (security), bullseye | 9.0.43-2~deb11u6 | fixed | |
bookworm | 9.0.70-1 | fixed | |
sid | 9.0.70-2 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
tomcat8 | source | jessie | (not affected) | |||
tomcat8 | source | stretch | (not affected) | |||
tomcat8 | source | (unstable) | (unfixed) | 30873 | ||
tomcat9 | source | buster | 9.0.31-1~deb10u1 | DSA-4680-1 | ||
tomcat9 | source | (unstable) | 9.0.22-1 | 930872, 931131 |
[stretch] - tomcat8 <not-affected> (Incomplete fix for CVE-2019-0199 not applied)
[jessie] - tomcat8 <not-affected> (HTTP/2 support not implemented)
https://lists.apache.org/thread.html/df1a2c1b87c8a6c500ecdbbaf134c7f1491c8d79d98b48c6b9f0fa6a@%3Cannounce.tomcat.apache.org%3E