File _patchinfo of Package patchinfo.8118

<patchinfo incident="8118">
  <issue id="1102379" tracker="bnc">VUL-0: CVE-2018-8034: tomcat: host name verification missing in WebSocket client</issue>
  <issue id="1102400" tracker="bnc">VUL-0: CVE-2018-1336: tomcat: A bug in the UTF-8 decoder can lead to DoS</issue>
  <issue id="1102410" tracker="bnc">VUL-0: CVE-2018-8037: tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up</issue>
  <issue id="2018-1336" tracker="cve" />
  <issue id="2018-8034" tracker="cve" />
  <issue id="2018-8037" tracker="cve" />
  <issue tracker="bnc" id="1067720">/etc/sysconfig/tomcat is being overwritten when updated.</issue>
  <issue tracker="bnc" id="1093697">VUL-1: CVE-2018-8014: tomcat: The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials'</issue>
  <issue tracker="bnc" id="1095472">File conflict with /etc/ant.d/catalina-ant</issue>
  <issue tracker="cve" id="2018-8014"/>
  <category>security</category>
  <rating>moderate</rating>
  <packager>mateialbu</packager>
  <description>This update for tomcat to 8.0.53 fixes the following issues:

Security issue fixed:

- CVE-2018-1336: An improper handing of overflow in the UTF-8 decoder with
  supplementary characters could have lead to an infinite loop in the decoder
  causing a Denial of Service (bsc#1102400).
- CVE-2018-8034: The host name verification when using TLS with the WebSocket
  client was missing. It is now enabled by default (bsc#1102379).
- CVE-2018-8037: If an async request was completed by the application at the
  same time as the container triggered the async timeout, a race condition
  existed that could have resulted in a user seeing a response intended for a
  different user. An additional issue was present in the NIO and NIO2 connectors
  that did not correctly track the closure of the connection when an async
  request was completed by the application and timed out by the container at the
  same time. This could also have resulted in a user seeing a response intended
  for another user (bsc#1102410).
- CVE-2018-8014: Fix insecure default CORS filter settings (bsc#1093697).

Bug fixes:

- bsc#1067720: Avoid overwriting of customer's configuration during update.
- bsc#1095472: Add Obsoletes for tomcat6 packages.
</description>
  <summary>Security update for tomcat</summary>
</patchinfo>
openSUSE Build Service is sponsored by