Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Red Hat Enterprise Linux 8: Security Fix for pki-deps RHSA-2019-1529-01

red hat
Calendar Grey June 18, 2019
Dist Redhat Esm H88
Ubuntu introduces an important software patch for the apache-server:2.4 package, addressing multiple vulnerabilities in the web application framework.
An update for the pki-deps:10.6 module is now available for Red Hat Enterprise Linux 8

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by Red Hat Certificate System.
Security Fix(es):
* tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up (CVE-2018-8037)
* tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins (CVE-2018-8014)
* tomcat: Open redirect in default servlet (CVE-2018-11784)
* tomcat: Host name verification missing in WebSocket client (CVE-2018-8034)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2018-8014 https://access.redhat.com/security/cve/CVE-2018-8034 https://access.redhat.com/security/cve/CVE-2018-8037 https://access.redhat.com/security/cve/CVE-2018-11784 https://access.redhat.com/security/updates/classification/#important

Package List

Red Hat Enterprise Linux AppStream (v. 8):
Source: apache-commons-collections-3.2.2-10.module+el8.0.0+3248+9d514f3b.src.rpm apache-commons-lang-2.6-21.module+el8.0.0+3248+9d514f3b.src.rpm bea-stax-1.2.0-16.module+el8.0.0+3248+9d514f3b.src.rpm glassfish-fastinfoset-1.2.13-9.module+el8.0.0+3248+9d514f3b.src.rpm glassfish-jaxb-2.2.11-11.module+el8.0.0+3248+9d514f3b.src.rpm glassfish-jaxb-api-2.2.12-8.module+el8.0.0+3248+9d514f3b.src.rpm jackson-annotations-2.9.8-1.module+el8.0.0+3248+9d514f3b.src.rpm jackson-core-2.9.8-1.module+el8.0.0+3248+9d514f3b.src.rpm jackson-databind-2.9.8-1.module+el8.0.0+3248+9d514f3b.src.rpm jackson-jaxrs-providers-2.9.8-1.module+el8.0.0+3248+9d514f3b.src.rpm jackson-module-jaxb-annotations-2.7.6-4.module+el8.0.0+3248+9d514f3b.src.rpm jakarta-commons-httpclient-3.1-28.module+el8.0.0+3248+9d514f3b.src.rpm javassist-3.18.1-8.module+el8.0.0+3248+9d514f3b.src.rpm pki-servlet-container-9.0.7-14.module+el8.0.0+3248+9d514f3b.src.rpm python-nss-1.0.1-10.module+el8.0.0+3248+9d514f3b.src.rpm relaxngDatatype-2011.1-7.module+el8.0.0+3248+9d514f3b.src.rpm resteasy-3.0.26-3.module+el8.0.0+3248+9d514f3b.src.rpm slf4j-1.7.25-4.module+el8.0.0+3248+9d514f3b.src.rpm stax-ex-1.7.7-8.module+el8.0.0+3248+9d514f3b.src.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2019:1529-01
Product: Red Hat Enterprise Linux
Advisory URL:
Issue date: 2019-06-18

Topic

An update for the pki-deps:10.6 module is now available for Red HatEnterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64

Bugs Fixed

1579611 - CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins

1607580 - CVE-2018-8034 tomcat: Host name verification missing in WebSocket client

1607582 - CVE-2018-8037 tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up

1636512 - CVE-2018-11784 tomcat: Open redirect in default servlet

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here