Gnoppix Security has released GSA-6328-1 to fix a critical vulnerability in the Tomcat 10 servlet container. The flaw allows remote attackers to perform HTTP request smuggling, potentially leading to cache poisoning or session hijacking.
Vulnerability Details
The issue affects all Tomcat 10 installations on Gnoppix 23/25 and Gnoppix 25. Attackers can exploit malformed HTTP headers to poison the request stream.
Critical Risk: Unpatched systems may allow remote code execution in combination with other flaws.
Affected Packages
- tomcat10 – all versions prior to the updated packages in GSA-6328-1.
Action Required
- Upgrade immediately to the fixed tomcat10 package.
- Restart the service after installation for changes to take effect.
Background
The vulnerability was discovered during internal security testing. No active exploitation has been reported yet. The updated packages are available in the Gnoppix 23/25 and Gnoppix 25 security repositories. - Please update your systems.