Chapter 4. Security Fixes
This release includes fixes for the following security-related issues:
| ID | Impact | Summary |
|---|---|---|
| Important | tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS [jws-5] | |
| Moderate | tomcat: HTTP request smuggling when used with a reverse proxy [jws-5] | |
| Moderate | openssl: NULL pointer dereference in X509_issuer_and_serial_hash() [jws-5] | |
| Moderate | openssl: integer overflow in CipherUpdate [jws-5] | |
| Moderate | openssl: Read buffer overruns processing ASN.1 strings [jws-5] | |
| Low | tomcat: JNDI realm authentication weakness [jws-5] |