Shellinabox, Ruby, Jetty, Tomcat, ZFS-Linux, OpenJPEG2, Tomcat updates for Debian

Published by

Debian GNU/Linux has recently issued several critical security updates across different versions, addressing vulnerabilities in various packages including Shellinabox, Ruby, Jetty, Tomcat, ZFS-Linux, and OpenJPEG2. Here’s a summary of the updates provided for various Debian releases:

1. Debian GNU/Linux 8 (Jessie) ELTS:
- Tomcat7 (ELA-1378-1): Security updates addressing vulnerabilities.

2. Debian GNU/Linux 8 (Jessie) and 9 (Stretch) ELTS:
- OpenJPEG2 (ELA-1380-1): Updates for security vulnerabilities.
- Tomcat8 (ELA-1377-1): Security patches to mitigate vulnerabilities.

3. Debian GNU/Linux 9 (Stretch) ELTS:
- Shellinabox (ELA-1375-1): Fixes a denial of service vulnerability.
- Ruby2.3 (ELA-1374-1): Multiple vulnerabilities addressed, including denial of service risks due to uncapped cookie sizes and regex issues.

4. Debian GNU/Linux 10 (Buster) ELTS:
- OpenJPEG2 (ELA-1379-1): Updates addressing buffer overflow vulnerabilities.
- Tomcat9 (ELA-1376-1): Security vulnerabilities fixed, including potential remote code execution.

5. Debian GNU/Linux 11 (Bullseye) LTS:
- Ruby-saml (DLA 4115-1): Updates to mitigate authentication bypass and denial of service vulnerabilities.
- Jetty9 (DLA 4106-2): Regression fixes for previous updates.
- ZFS-Linux (DLA 4114-1): Security vulnerabilities addressed to prevent unauthorized access and data corruption.

6. Debian GNU/Linux 12 (Bookworm):
- Jetty9 (DSA 5894-1): Updates addressing multiple vulnerabilities that could lead to denial of service.
- Tomcat10 (DSA 5893-1): A vulnerability allowing unauthorized access to sensitive files was patched.

These updates highlight the ongoing commitment of the Debian community to maintain security and stability across its distributions. Users are encouraged to promptly upgrade their packages to mitigate risks associated with these vulnerabilities.

Extension: In addition to these critical updates, it is essential for users to regularly monitor the Debian security advisory pages and subscribe to mailing lists for the latest security notifications. This proactive approach ensures that systems remain protected against emerging threats. Furthermore, users should consider employing best practices such as regular backups, employing firewalls, and using intrusion detection systems to further enhance their security posture. Additionally, organizations may benefit from conducting security audits to identify and rectify vulnerabilities in their systems

Shellinabox, Ruby, Jetty, Tomcat, ZFS-Linux, OpenJPEG2, Tomcat updates for Debian

Debian GNU/Linux has been updated with multiple security enhancements, including Shellinabox, Ruby, Jetty, Tomcat, ZFS-Linux, OpenJPEG2, and Tomcat:

Debian GNU/Linux 8 (Jessie) ELTS:
ELA-1378-1 tomcat7 security update

Debian GNU/Linux 8 (Jessie) and 9 (Stretch) ELTS:
ELA-1380-1 openjpeg2 security update
ELA-1377-1 tomcat8 security update

Debian GNU/Linux 9 (Stretch) ELTS:
ELA-1375-1 shellinabox security update
ELA-1374-1 ruby2.3 security update

Debian GNU/Linux 10 (Buster) ELTS:
ELA-1379-1 openjpeg2 security update
ELA-1376-1 tomcat9 security update

Debian GNU/Linux 11 (Bullseye) LTS:
[DLA 4115-1] ruby-saml security update
[DLA 4106-2] jetty9 regression update
[DLA 4114-1] zfs-linux security update

Debian GNU/Linux 12 (Bookworm):
[DSA 5894-1] jetty9 security update
[DSA 5893-1] tomcat10 security update

Shellinabox, Ruby, Jetty, Tomcat, ZFS-Linux, OpenJPEG2, Tomcat updates for Debian @ Linux Compatible