MGASA-2017-0277
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 18 Aug 2017, 17:06
Last modified:16 Apr 2026, 06:23
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
18 Aug 2017, 17:06
Published
Vulnerability first disclosed
16 Apr 2026, 06:23
Last Modified
Vulnerability information updated
Description
Updated jetty packages fix security vulnerability Jetty is prone to a timing channel attack in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords (CVE-2017-9735).
Affected Systems
- mageia•jetty
< 9.4.6-1.v20170531.1.1.mga6
- mageia•jetty-alpn
< 8.1.11-3.v20170118.1.mga6
- mageia•jetty-test-helper
< 3.1-4.mga6