Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
Red Hat JBoss Web Server is a fully integrated and certified set of
components for hosting Java web applications. It is comprised of the Apache
Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the
PicketLink Vault extension for Apache Tomcat, and the Tomcat Native
library.
This release of Red Hat JBoss Web Server 5.5.1 serves as a replacement for
Red Hat JBoss Web Server 5.5.0, and includes bug fixes, enhancements and
component upgrades, which are documented in the Release Notes, linked to in
the References.
Security Fix(es):
* tomcat: Apache Tomcat DoS with unexpected TLS packet (CVE-2021-41079)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
https://access.redhat.com/security/cve/CVE-2021-41079 https://access.redhat.com/security/updates/classification#important
Red Hat JBoss Web Server 5.5 for RHEL 7 Server:
Source:
jws5-tomcat-9.0.43-13.redhat_00013.1.el7jws.src.rpm
noarch:
jws5-tomcat-9.0.43-13.redhat_00013.1.el7jws.noarch.rpm
jws5-tomcat-admin-webapps-9.0.43-13.redhat_00013.1.el7jws.noarch.rpm
jws5-tomcat-docs-webapp-9.0.43-13.redhat_00013.1.el7jws.noarch.rpm
jws5-tomcat-el-3.0-api-9.0.43-13.redhat_00013.1.el7jws.noarch.rpm
jws5-tomcat-java-jdk11-9.0.43-13.redhat_00013.1.el7jws.noarch.rpm
jws5-tomcat-java-jdk8-9.0.43-13.redhat_00013.1.el7jws.noarch.rpm
jws5-tomcat-javadoc-9.0.43-13.redhat_00013.1.el7jws.noarch.rpm
jws5-tomcat-jsp-2.3-api-9.0.43-13.redhat_00013.1.el7jws.noarch.rpm
jws5-tomcat-lib-9.0.43-13.redhat_00013.1.el7jws.noarch.rpm
jws5-tomcat-selinux-9.0.43-13.redhat_00013.1.el7jws.noarch.rpm
jws5-tomcat-servlet-4.0-api-9.0.43-13.redhat_00013.1.el7jws.noarch.rpm
jws5-tomcat-webapps-9.0.43-13.redhat_00013.1.el7jws.noarch.rpm
Red Hat JBoss Web Server 5.5 for RHEL 8:
Source:
jws5-tomcat-9.0.43-13.redhat_00013.1.el8jws.src.rpm
noarch:
jws5-tomcat-9.0.43-13.redhat_00013.1.el8jws.noarch.rpm
jws5-tomcat-admin-webapps-9.0.43-13.redhat_00013.1.el8jws.noarch.rpm
jws5-tomcat-docs-webapp-9.0.43-13.redhat_00013.1.el8jws.noarch.rpm
jws5-tomcat-el-3.0-api-9.0.43-13.redhat_00013.1.el8jws.noarch.rpm
Read the Full Advisory
Updated Red Hat JBoss Web Server 5.5.1 packages are now available for RedHat Enterprise Linux 7 and Red Hat Enterprise Linux 8.Red Hat Product Security has rated this release as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat JBoss Web Server 5.5 for RHEL 7 Server - noarch
Red Hat JBoss Web Server 5.5 for RHEL 8 - noarch
2004820 - CVE-2021-41079 tomcat: Infinite loop while reading an unexpected TLS packet when using OpenSSL JSSE engine
Get the latest Linux and open source security news straight to your inbox.