Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
172

Ubuntu 24.04 LTS USN-6729-3 Moderate: Apache2 HTTP Server DoS Threats

Several security issues were fixed in Apache HTTP Server.. ========================================================================== Ubuntu Security Notice USN-6729-3 April 29, 2024 apache2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in Apache HTTP Server. Software Description: - apache2: Apache HTTP server Details: USN-6729-1 fixed vulnerabilities in Apache HTTP Server. This update provides the corresponding updates for Ubuntu 24.04 LTS. Original advisory details: Orange Tsai discovered that the Apache HTTP Server incorrectly handled validating certain input. A remote attacker could possibly use this issue to perform HTTP request splitting attacks. (CVE-2023-38709) Keran Mu and Jianjun Chen discovered that the Apache HTTP Server incorrectly handled validating certain input. A remote attacker could possibly use this issue to perform HTTP request splitting attacks. (CVE-2024-24795) Bartek Nowotarski discovered that the Apache HTTP Server HTTP/2 module incorrectly handled endless continuation frames. A remote attacker could possibly use this issue to cause the server to consume resources, leading to a denial of service. (CVE-2024-27316) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS apache2 2.4.58-1ubuntu8.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6729-3 https://ubuntu.com/security/notices/USN-6729-1 CVE-2023-38709, CVE-2024-24795, CVE-2024-27316 Package Information: https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.1 . Applied multiple security patches for Nginx on Ubuntu 24.04 LTS to resolve significant vulnerabilitiesimpacting overall security.. apache security update, ubuntu apache advisory, apache2 vulnerability fixes, web server security, ubuntu 24.04 apache. . LinuxSecurity.com Team

Calendar%202 Apr 29, 2024 Ubuntu
98

Red Hat 7/8 Critical: RHSA-2023:3354-01 Apache HTTP Server Update

An update is now available for Red Hat JBoss Core Services Apache HTTP Server 2.4.51 Service Pack 2 on Red Hat Enterprise Linux versions 7 and 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat JBoss Core Services Apache HTTP Server 2.4.51 SP2 security update Advisory ID: RHSA-2023:3354-01 Product: Red Hat JBoss Core Services Advisory URL: https://access.redhat.com/errata/RHSA-2023:3354 Issue date: 2023-06-05 CVE Names: CVE-2006-20001 CVE-2022-4304 CVE-2022-4450 CVE-2022-25147 CVE-2022-43551 CVE-2022-43552 CVE-2023-0215 CVE-2023-0286 CVE-2023-23914 CVE-2023-23915 CVE-2023-23916 CVE-2023-25690 ==================================================================== 1. Summary: An update is now available for Red Hat JBoss Core Services Apache HTTP Server 2.4.51 Service Pack 2 on Red Hat Enterprise Linux versions 7 and 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat JBoss Core Services on RHEL 7 Server - noarch, x86_64 Red Hat JBoss Core Services on RHEL 8 - noarch, x86_64 3. Description: Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products, and is packaged under Red Hat JBoss Core Services to allow for faster distribution of updates, and for a more consistent update experience. This release of Red Hat JBoss CoreServices Apache HTTP Server 2.4.51 Service Pack 2 serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.51 Service Pack 1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Security Fix(es): * apr-util: out-of-bounds writes in the apr_base64 (CVE-2022-25147) * curl: HSTS bypass via IDN (CVE-2022-43551) * curl: HTTP Proxy deny use-after-free (CVE-2022-43552) * curl: HSTS ignored on multiple requests (CVE-2023-23914) * curl: HSTS amnesia with --parallel (CVE-2023-23915) * curl: HTTP multi-header compression denial of service (CVE-2023-23916) * httpd: mod_dav: out-of-bounds read/write of zero byte (CVE-2006-20001) * httpd: HTTP request splitting with mod_rewrite and mod_proxy (CVE-2023-25690) * openssl: timing attack in RSA Decryption implementation (CVE-2022-4304) * openssl: double free after calling PEM_read_bio_ex (CVE-2022-4450) * openssl: use-after-free following BIO_new_NDEF (CVE-2023-0215) * openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Applications using the APR libraries, such as httpd, must be restarted for this update to take effect. After installing the updated packages, the httpd daemon will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 2152639 - CVE-2022-43551 curl: HSTS bypass via IDN 2152652 - CVE-2022-43552 curl: Use-after-free triggered by an HTTP proxy deny response 2161774 - CVE-2006-20001 httpd: mod_dav: out-of-bounds read/write of zero byte 2164440 - CVE-2023-0286 openssl: X.400 address type confusion in X.509 GeneralName 2164487 - CVE-2022-4304 openssl: timing attack in RSA Decryptionimplementation 2164492 - CVE-2023-0215 openssl: use-after-free following BIO_new_NDEF 2164494 - CVE-2022-4450 openssl: double free after calling PEM_read_bio_ex 2167797 - CVE-2023-23914 curl: HSTS ignored on multiple requests 2167813 - CVE-2023-23915 curl: HSTS amnesia with --parallel 2167815 - CVE-2023-23916 curl: HTTP multi-header compression denial of service 2169652 - CVE-2022-25147 apr-util: out-of-bounds writes in the apr_base64 2176209 - CVE-2023-25690 httpd: HTTP request splitting with mod_rewrite and mod_proxy 6. Package List: Red Hat JBoss Core Services on RHEL 7Server: Source: jbcs-httpd24-apr-util-1.6.1-101.el7jbcs.src.rpm jbcs-httpd24-curl-8.0.1-1.el7jbcs.src.rpm jbcs-httpd24-httpd-2.4.51-39.el7jbcs.src.rpm jbcs-httpd24-mod_http2-1.15.19-23.el7jbcs.src.rpm jbcs-httpd24-mod_jk-1.2.48-46.redhat_1.el7jbcs.src.rpm jbcs-httpd24-mod_md-2.4.0-20.el7jbcs.src.rpm jbcs-httpd24-mod_proxy_cluster-1.3.18-2.el7jbcs.src.rpm jbcs-httpd24-mod_security-2.9.3-24.el7jbcs.src.rpm jbcs-httpd24-openssl-1.1.1k-14.el7jbcs.src.rpm jbcs-httpd24-openssl-chil-1.0.0-18.el7jbcs.src.rpm jbcs-httpd24-openssl-pkcs11-0.4.10-33.el7jbcs.src.rpm noarch: jbcs-httpd24-httpd-manual-2.4.51-39.el7jbcs.noarch.rpm x86_64: jbcs-httpd24-apr-util-1.6.1-101.el7jbcs.x86_64.rpm jbcs-httpd24-apr-util-debuginfo-1.6.1-101.el7jbcs.x86_64.rpm jbcs-httpd24-apr-util-devel-1.6.1-101.el7jbcs.x86_64.rpm jbcs-httpd24-apr-util-ldap-1.6.1-101.el7jbcs.x86_64.rpm jbcs-httpd24-apr-util-mysql-1.6.1-101.el7jbcs.x86_64.rpm jbcs-httpd24-apr-util-nss-1.6.1-101.el7jbcs.x86_64.rpm jbcs-httpd24-apr-util-odbc-1.6.1-101.el7jbcs.x86_64.rpm jbcs-httpd24-apr-util-openssl-1.6.1-101.el7jbcs.x86_64.rpm jbcs-httpd24-apr-util-pgsql-1.6.1-101.el7jbcs.x86_64.rpm jbcs-httpd24-apr-util-sqlite-1.6.1-101.el7jbcs.x86_64.rpm jbcs-httpd24-curl-8.0.1-1.el7jbcs.x86_64.rpm jbcs-httpd24-curl-debuginfo-8.0.1-1.el7jbcs.x86_64.rpm jbcs-httpd24-httpd-2.4.51-39.el7jbcs.x86_64.rpm jbcs-httpd24-httpd-debuginfo-2.4.51-39.el7jbcs.x86_64.rpm jbcs-httpd24-httpd-devel-2.4.51-39.el7jbcs.x86_64.rpm jbcs-httpd24-httpd-selinux-2.4.51-39.el7jbcs.x86_64.rpm jbcs-httpd24-httpd-tools-2.4.51-39.el7jbcs.x86_64.rpm jbcs-httpd24-libcurl-8.0.1-1.el7jbcs.x86_64.rpm jbcs-httpd24-libcurl-devel-8.0.1-1.el7jbcs.x86_64.rpm jbcs-httpd24-mod_http2-1.15.19-23.el7jbcs.x86_64.rpm jbcs-httpd24-mod_http2-debuginfo-1.15.19-23.el7jbcs.x86_64.rpm jbcs-httpd24-mod_jk-ap24-1.2.48-46.redhat_1.el7jbcs.x86_64.rpm jbcs-httpd24-mod_jk-debuginfo-1.2.48-46.redhat_1.el7jbcs.x86_64.rpm jbcs-httpd24-mod_ldap-2.4.51-39.el7jbcs.x86_64.rpm jbcs-httpd24-mod_md-2.4.0-20.el7jbcs.x86_64.rpm jbcs-httpd24-mod_md-debuginfo-2.4.0-20.el7jbcs.x86_64.rpm jbcs-httpd24-mod_proxy_cluster-1.3.18-2.el7jbcs.x86_64.rpm jbcs-httpd24-mod_proxy_cluster-debuginfo-1.3.18-2.el7jbcs.x86_64.rpm jbcs-httpd24-mod_proxy_html-2.4.51-39.el7jbcs.x86_64.rpm jbcs-httpd24-mod_security-2.9.3-24.el7jbcs.x86_64.rpm jbcs-httpd24-mod_security-debuginfo-2.9.3-24.el7jbcs.x86_64.rpm jbcs-httpd24-mod_session-2.4.51-39.el7jbcs.x86_64.rpm jbcs-httpd24-mod_ssl-2.4.51-39.el7jbcs.x86_64.rpm jbcs-httpd24-openssl-1.1.1k-14.el7jbcs.x86_64.rpm jbcs-httpd24-openssl-chil-1.0.0-18.el7jbcs.x86_64.rpm jbcs-httpd24-openssl-chil-debuginfo-1.0.0-18.el7jbcs.x86_64.rpm jbcs-httpd24-openssl-debuginfo-1.1.1k-14.el7jbcs.x86_64.rpm jbcs-httpd24-openssl-devel-1.1.1k-14.el7jbcs.x86_64.rpm jbcs-httpd24-openssl-libs-1.1.1k-14.el7jbcs.x86_64.rpm jbcs-httpd24-openssl-perl-1.1.1k-14.el7jbcs.x86_64.rpm jbcs-httpd24-openssl-pkcs11-0.4.10-33.el7jbcs.x86_64.rpm jbcs-httpd24-openssl-pkcs11-debuginfo-0.4.10-33.el7jbcs.x86_64.rpm jbcs-httpd24-openssl-static-1.1.1k-14.el7jbcs.x86_64.rpm Red Hat JBoss Core Services on RHEL8: Source: jbcs-httpd24-apr-util-1.6.1-101.el8jbcs.src.rpm jbcs-httpd24-curl-8.0.1-1.el8jbcs.src.rpm jbcs-httpd24-httpd-2.4.51-39.el8jbcs.src.rpm jbcs-httpd24-mod_http2-1.15.19-23.el8jbcs.src.rpm jbcs-httpd24-mod_jk-1.2.48-46.redhat_1.el8jbcs.src.rpm jbcs-httpd24-mod_md-2.4.0-20.el8jbcs.src.rpm jbcs-httpd24-mod_proxy_cluster-1.3.18-2.el8jbcs.src.rpm jbcs-httpd24-mod_security-2.9.3-24.el8jbcs.src.rpm jbcs-httpd24-openssl-1.1.1k-14.el8jbcs.src.rpm jbcs-httpd24-openssl-chil-1.0.0-18.el8jbcs.src.rpm jbcs-httpd24-openssl-pkcs11-0.4.10-33.el8jbcs.src.rpm noarch: jbcs-httpd24-httpd-manual-2.4.51-39.el8jbcs.noarch.rpm x86_64: jbcs-httpd24-apr-util-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-debuginfo-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-devel-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-ldap-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-ldap-debuginfo-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-mysql-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-mysql-debuginfo-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-nss-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-nss-debuginfo-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-odbc-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-odbc-debuginfo-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-openssl-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-openssl-debuginfo-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-pgsql-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-pgsql-debuginfo-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-sqlite-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-apr-util-sqlite-debuginfo-1.6.1-101.el8jbcs.x86_64.rpm jbcs-httpd24-curl-8.0.1-1.el8jbcs.x86_64.rpm jbcs-httpd24-curl-debuginfo-8.0.1-1.el8jbcs.x86_64.rpm jbcs-httpd24-httpd-2.4.51-39.el8jbcs.x86_64.rpm jbcs-httpd24-httpd-debuginfo-2.4.51-39.el8jbcs.x86_64.rpm jbcs-httpd24-httpd-devel-2.4.51-39.el8jbcs.x86_64.rpm jbcs-httpd24-httpd-selinux-2.4.51-39.el8jbcs.x86_64.rpm jbcs-httpd24-httpd-tools-2.4.51-39.el8jbcs.x86_64.rpm jbcs-httpd24-httpd-tools-debuginfo-2.4.51-39.el8jbcs.x86_64.rpm jbcs-httpd24-libcurl-8.0.1-1.el8jbcs.x86_64.rpm jbcs-httpd24-libcurl-debuginfo-8.0.1-1.el8jbcs.x86_64.rpm jbcs-httpd24-libcurl-devel-8.0.1-1.el8jbcs.x86_64.rpm jbcs-httpd24-mod_http2-1.15.19-23.el8jbcs.x86_64.rpm jbcs-httpd24-mod_http2-debuginfo-1.15.19-23.el8jbcs.x86_64.rpm jbcs-httpd24-mod_jk-ap24-1.2.48-46.redhat_1.el8jbcs.x86_64.rpm jbcs-httpd24-mod_jk-ap24-debuginfo-1.2.48-46.redhat_1.el8jbcs.x86_64.rpm jbcs-httpd24-mod_ldap-2.4.51-39.el8jbcs.x86_64.rpm jbcs-httpd24-mod_ldap-debuginfo-2.4.51-39.el8jbcs.x86_64.rpm jbcs-httpd24-mod_md-2.4.0-20.el8jbcs.x86_64.rpm jbcs-httpd24-mod_md-debuginfo-2.4.0-20.el8jbcs.x86_64.rpm jbcs-httpd24-mod_proxy_cluster-1.3.18-2.el8jbcs.x86_64.rpm jbcs-httpd24-mod_proxy_cluster-debuginfo-1.3.18-2.el8jbcs.x86_64.rpm jbcs-httpd24-mod_proxy_html-2.4.51-39.el8jbcs.x86_64.rpm jbcs-httpd24-mod_proxy_html-debuginfo-2.4.51-39.el8jbcs.x86_64.rpm jbcs-httpd24-mod_security-2.9.3-24.el8jbcs.x86_64.rpm jbcs-httpd24-mod_security-debuginfo-2.9.3-24.el8jbcs.x86_64.rpm jbcs-httpd24-mod_session-2.4.51-39.el8jbcs.x86_64.rpm jbcs-httpd24-mod_session-debuginfo-2.4.51-39.el8jbcs.x86_64.rpm jbcs-httpd24-mod_ssl-2.4.51-39.el8jbcs.x86_64.rpm jbcs-httpd24-mod_ssl-debuginfo-2.4.51-39.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-1.1.1k-14.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-chil-1.0.0-18.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-chil-debuginfo-1.0.0-18.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-debuginfo-1.1.1k-14.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-devel-1.1.1k-14.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-libs-1.1.1k-14.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-libs-debuginfo-1.1.1k-14.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-perl-1.1.1k-14.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-pkcs11-0.4.10-33.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-pkcs11-debuginfo-0.4.10-33.el8jbcs.x86_64.rpm jbcs-httpd24-openssl-static-1.1.1k-14.el8jbcs.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2006-20001 https://access.redhat.com/security/cve/CVE-2022-4304 https://access.redhat.com/security/cve/CVE-2022-4450 https://access.redhat.com/security/cve/CVE-2022-25147 https://access.redhat.com/security/cve/CVE-2022-43551 https://access.redhat.com/security/cve/CVE-2022-43552 https://access.redhat.com/security/cve/CVE-2023-0215 https://access.redhat.com/security/cve/CVE-2023-0286 https://access.redhat.com/security/cve/CVE-2023-23914 https://access.redhat.com/security/cve/CVE-2023-23915 https://access.redhat.com/security/cve/CVE-2023-23916 https://access.redhat.com/security/cve/CVE-2023-25690 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZH4jO9zjgjWX9erEAQhdzQ//WjNcrrZ2U8gZyEoQSCNUuGWPbKkm9H5e bdaRIBdB+st5qK0c114J+jSozhjpTsY3FvKVQaIvO5HVpQLXgJZEAjWjTCJPF0R6 zEafAjK8UennjPkXzH7kYfXrGMIyDh+aMj0QN+SQM2IyD34W0Zk3uwjRnO1RlwCN PuPv9RxSTa8SbFAoYkmvI9N1e73Qiwv/50m9dN6DSo1jpLIhiiG15GIB0baoOS05 5Vh8haPq9jmbsHjdyEdDNifgruwm/OipaS6QrcB21T2f0Tsy3Kvn7oUbXC5NxKWZ 1H5RWEnVhFA+pfeY5ZChVYuktqFuhhhsnCcdLzMrzNsDquZXcKP/sRG4Lg6EjrOr sv7ywIgIEAYrHSuXj+b4Bkx1NRKZtMknsfi9Mw3vCARAqvIapBNIthC4dqg0gIiS HoXtsZDoz7GGcguOpcrMuzPOaiJiS8u9M8068JT6k20DSAM/jmL/mkzhaw2GG+KV MRLIaJViehUCrxJ4eht+djH4Mv8aEORWJx81yG91IKsH7nMcBkvqYsHf1qBxm78T L8L1va2P9tS1tA4Dbfp8aKr/Jr/ocMOJhapGCMNnAwsAUErgaGYOSVbYo4Bp2hrG FCsgWJWCB6NQwvRv/CZXar5AMvmVlrOVqYEHjMVQBfVS3Bu12a12EGKtnO3fJAYa 2SvVnChgmv4=TkYq -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial enhancement released for Red Hat JBoss Core Services to resolve various vulnerabilities in Apache HTTP Server.. Apache HTTP Server Update, JBoss Security Advisory, Red Hat JBoss Services, Important Security Update. . Severity: Important.LinuxSecurity.com Team

Calendar%202 Jun 05, 2023 Important Red Hat
98

Red Hat 7: RHSA-2023-1593-01 Important: httpd Request Splitting

An update for httpd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: httpd security update Advisory ID: RHSA-2023:1593-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1593 Issue date: 2023-04-04 CVE Names: CVE-2023-25690 ==================================================================== 1. Summary: An update for httpd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): * httpd: HTTP request splitting with mod_rewrite and mod_proxy (CVE-2023-25690) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how toapply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 2176209 - CVE-2023-25690 httpd: HTTP request splitting with mod_rewrite and mod_proxy 6. Package List: Red Hat Enterprise Linux Client Optional (v. 7): Source: httpd-2.4.6-98.el7_9.7.src.rpm noarch: httpd-manual-2.4.6-98.el7_9.7.noarch.rpm x86_64: httpd-2.4.6-98.el7_9.7.x86_64.rpm httpd-debuginfo-2.4.6-98.el7_9.7.x86_64.rpm httpd-devel-2.4.6-98.el7_9.7.x86_64.rpm httpd-tools-2.4.6-98.el7_9.7.x86_64.rpm mod_ldap-2.4.6-98.el7_9.7.x86_64.rpm mod_proxy_html-2.4.6-98.el7_9.7.x86_64.rpm mod_session-2.4.6-98.el7_9.7.x86_64.rpm mod_ssl-2.4.6-98.el7_9.7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): Source: httpd-2.4.6-98.el7_9.7.src.rpm noarch: httpd-manual-2.4.6-98.el7_9.7.noarch.rpm x86_64: httpd-2.4.6-98.el7_9.7.x86_64.rpm httpd-debuginfo-2.4.6-98.el7_9.7.x86_64.rpm httpd-devel-2.4.6-98.el7_9.7.x86_64.rpm httpd-tools-2.4.6-98.el7_9.7.x86_64.rpm mod_ldap-2.4.6-98.el7_9.7.x86_64.rpm mod_proxy_html-2.4.6-98.el7_9.7.x86_64.rpm mod_session-2.4.6-98.el7_9.7.x86_64.rpm mod_ssl-2.4.6-98.el7_9.7.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: httpd-2.4.6-98.el7_9.7.src.rpm noarch: httpd-manual-2.4.6-98.el7_9.7.noarch.rpm ppc64: httpd-2.4.6-98.el7_9.7.ppc64.rpm httpd-debuginfo-2.4.6-98.el7_9.7.ppc64.rpm httpd-devel-2.4.6-98.el7_9.7.ppc64.rpm httpd-tools-2.4.6-98.el7_9.7.ppc64.rpm mod_session-2.4.6-98.el7_9.7.ppc64.rpm mod_ssl-2.4.6-98.el7_9.7.ppc64.rpm ppc64le: httpd-2.4.6-98.el7_9.7.ppc64le.rpm httpd-debuginfo-2.4.6-98.el7_9.7.ppc64le.rpm httpd-devel-2.4.6-98.el7_9.7.ppc64le.rpm httpd-tools-2.4.6-98.el7_9.7.ppc64le.rpm mod_session-2.4.6-98.el7_9.7.ppc64le.rpm mod_ssl-2.4.6-98.el7_9.7.ppc64le.rpm s390x: httpd-2.4.6-98.el7_9.7.s390x.rpm httpd-debuginfo-2.4.6-98.el7_9.7.s390x.rpm httpd-devel-2.4.6-98.el7_9.7.s390x.rpm httpd-tools-2.4.6-98.el7_9.7.s390x.rpm mod_session-2.4.6-98.el7_9.7.s390x.rpm mod_ssl-2.4.6-98.el7_9.7.s390x.rpm x86_64: httpd-2.4.6-98.el7_9.7.x86_64.rpm httpd-debuginfo-2.4.6-98.el7_9.7.x86_64.rpm httpd-devel-2.4.6-98.el7_9.7.x86_64.rpm httpd-tools-2.4.6-98.el7_9.7.x86_64.rpm mod_session-2.4.6-98.el7_9.7.x86_64.rpm mod_ssl-2.4.6-98.el7_9.7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): ppc64: httpd-debuginfo-2.4.6-98.el7_9.7.ppc64.rpm mod_ldap-2.4.6-98.el7_9.7.ppc64.rpm mod_proxy_html-2.4.6-98.el7_9.7.ppc64.rpm ppc64le: httpd-debuginfo-2.4.6-98.el7_9.7.ppc64le.rpm mod_ldap-2.4.6-98.el7_9.7.ppc64le.rpm mod_proxy_html-2.4.6-98.el7_9.7.ppc64le.rpm s390x: httpd-debuginfo-2.4.6-98.el7_9.7.s390x.rpm mod_ldap-2.4.6-98.el7_9.7.s390x.rpm mod_proxy_html-2.4.6-98.el7_9.7.s390x.rpm x86_64: httpd-debuginfo-2.4.6-98.el7_9.7.x86_64.rpm mod_ldap-2.4.6-98.el7_9.7.x86_64.rpm mod_proxy_html-2.4.6-98.el7_9.7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: httpd-2.4.6-98.el7_9.7.src.rpm noarch: httpd-manual-2.4.6-98.el7_9.7.noarch.rpm x86_64: httpd-2.4.6-98.el7_9.7.x86_64.rpm httpd-debuginfo-2.4.6-98.el7_9.7.x86_64.rpm httpd-devel-2.4.6-98.el7_9.7.x86_64.rpm httpd-tools-2.4.6-98.el7_9.7.x86_64.rpm mod_session-2.4.6-98.el7_9.7.x86_64.rpm mod_ssl-2.4.6-98.el7_9.7.x86_64.rpm Red Hat Enterprise LinuxWorkstation Optional (v. 7): x86_64: httpd-debuginfo-2.4.6-98.el7_9.7.x86_64.rpm mod_ldap-2.4.6-98.el7_9.7.x86_64.rpm mod_proxy_html-2.4.6-98.el7_9.7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-25690 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZCw/FNzjgjWX9erEAQjM/w/9FYUd2qLJ+jwRERhmGRjw3SXsdmbHZXU+ Zg8atgtKPLRPBfcY+dCqXkctCWuqwXUgUkswFQfgMK9xYv2YKXPZU70r2ouB7xub jDBHAAaUtLpR+zwKqPmrjVvcOzYXx1OgKeG4wDROvOi94OM2sallCXDQuehW3C43 mVTV0x65r0pRDD28rQsQwJr3GiAhu2H4gE5L/5n708VJyRXKOI0YDlPu/hR2HDb0 PgtxXwCL8jUT1xsk1TPpH23JLqV5/PwgJFcdCgIZPJDBcIy7dd/VTFftVSdPzHLS pEaHMa9j4sYIR9/9rnadPwPTBh+QEeg4NlH2MiXHnXtW3H+nLHO2st9yF0WUZDSA CuOIjiguPnJh20mije3sCyWW8Wx7RcHypmHMdJFzxdXHhmr3Y8hyZY8/8edx6QV9 ZaXr1Q4p0ieSB6GOIkcXXhHxcklWYSO1jiL8R4wP6ZnaCS1cLNrIQXMc9o+iZ5iQ Z0NqYNP32FRQrN0tYMzqCA0Idarz7LXZ0tHDvxBp06MMpmk0tQUFhK+wsAjBXj5V yUBtpVmaHALyI8pDm4Wa7M3g4gxY3/fP2NQxwvNITQndH4RIWXk3TAHqPekoiM+v cOzHHWMljSNYAOTZQy3D5iocIiu13oROVjpHPeuHsleF0mQuE0TP7mLFwmSktlLO p9qd9hvH7to=biCH -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A crucial security patch for Apache on Red Hat Enterprise Linux 7 tackles request smuggling weaknesses.. Red Hat Security,httpd Update,Request Splitting,Linux Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 04, 2023 Important Red Hat
98

Red Hat JBoss: RHSA-2022:1390-01 Important HTTP Server Critical Update

Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 11 zip release for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows is available. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP11 security update Advisory ID: RHSA-2022:1390-01 Product: Red Hat JBoss Core Services Advisory URL: https://access.redhat.com/errata/RHSA-2022:1390 Issue date: 2022-04-20 CVE Names: CVE-2021-3516 CVE-2021-3517 CVE-2021-3518 CVE-2021-3537 CVE-2021-3541 CVE-2022-0778 CVE-2022-22720 CVE-2022-23308 ==================================================================== 1. Summary: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 11 zip release for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows is available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products, and is packaged under Red Hat JBoss Core Services to allow for faster distribution of updates, and for a more consistent update experience. This release adds the new Apache HTTP Server 2.4.37 Service Pack 11 packages that are part of the JBoss Core Services offering. This release serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 10 and includes bug fixes andenhancements. Refer to the Release Notes for information on the most significant bug fixes and enhancements included in this release. Security Fix(es): * jbcs-httpd24-httpd: httpd: HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier (CVE-2022-22720) * libxml2: use-after-free in xmlXIncludeDoProcess() in xinclude.c (CVE-2021-3518) * libxml2: heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c (CVE-2021-3517) * libxml2: use-after-free in xmlEncodeEntitiesInternal() in entities.c (CVE-2021-3516) * libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms (CVE-2021-3541) * libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode (CVE-2021-3537) * libxml2: Use-after-free of ID and IDREF attributes (CVE-2022-23308) * openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates (CVE-2022-0778) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. 4. Bugs fixed (https://bugzilla.redhat.com/): 1950515 - CVE-2021-3541 libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms 1954225 - CVE-2021-3516 libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c 1954232 - CVE-2021-3517 libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c 1954242 - CVE-2021-3518 libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c 1956522 - CVE-2021-3537 libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode 2056913 - CVE-2022-23308 libxml2: Use-after-free of ID and IDREFattributes 2062202 - CVE-2022-0778 openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates 2064321 - CVE-2022-22720 httpd: Errors encountered during the discarding of request body lead to HTTP request smuggling 5. References: https://access.redhat.com/security/cve/CVE-2021-3516 https://access.redhat.com/security/cve/CVE-2021-3517 https://access.redhat.com/security/cve/CVE-2021-3518 https://access.redhat.com/security/cve/CVE-2021-3537 https://access.redhat.com/security/cve/CVE-2021-3541 https://access.redhat.com/security/cve/CVE-2022-0778 https://access.redhat.com/security/cve/CVE-2022-22720 https://access.redhat.com/security/cve/CVE-2022-23308 https://access.redhat.com/security/updates/classification#important 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYmCHYdzjgjWX9erEAQjJjA//TlmKlXUIUrAzFHiX4FK6jnOSYJYvpzrm E4CfkuZuL6WO/ygsBTHjAtvx6t+qT7R+lppp9qCMjf9WAtOLe3IvLUNA9XLmC6bC V1WaZ7MafCRqUtoX6LSsxVqGZJuK2t4W5n0YVX1OdDBT3/1IxeztweKUN0exw8XV zmsfBCr8W/B6MwbICKGv3M0DhUkqAtNrBrhTcZeVdFfUOB1VZoIb4kNH3qj5o9kH 0xG/Bx3Phz9LuTEhTmb/Ze0jypXoLJPBntew8Ti38wAenwgDTy9pGeLYyCIFJn2Q tGU53FhiSsCxQT0Gy9JEiB+43zQNNFdO9wDl2mWTT3fAgt5rkBLLCcQ5u6vH2MDb MHV5jjWQq8TBEWoNOstbAOwTCLrjTQlb3B0wd5nXZFRVmKiBGfbrQN8TepnztzLU Q3O2vLw9dlLGWwAx5/gioolUzEpzh//ojnve30By7aHhoOyKBurWP4HlfS9kT/V8 sqi564YiWK6o5O3USUB08XRKKqcuaJ/Wj6MzNZNsLYgIw7pEx62AsuFIIHXGu4N4 QYYKYqyThck7GVUMkKEP7zAAqO7w1cBmT5RZdqtTPv3khfUL7Z0Xfr1Ze/cRRHbL H6hsmdpsToz3etPpkAzzRWRV4648gJtdeyLbk1GrqZvb2NOINhb6hjckesY8byfh ejI4MjWMI50=bUZn -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . Red Hat JBoss Core Services Apache patch addresses severe vulnerabilities. Discover essential fixes for organizational infrastructures.. Red Hat JBoss, Apache HTTP, Service Pack Update, Security Fix, Critical Updates. .Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 20, 2022 Important Red Hat
87

Debian: DSA-5040-1 High: Nginx Denial of Service and Memory Leak

Two vulnerabilities have been discovered in the Apache HTTP server: CVE-2021-44224 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5035-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff January 04, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : apache2 CVE ID : CVE-2021-44224 CVE-2021-44790 Two vulnerabilities have been discovered in the Apache HTTP server: CVE-2021-44224 When operating as a forward proxy, Apache was depending on the setup suspectible to denial of service or Server Side Request forgery. CVE-2021-44790 A buffer overflow in mod_lua may result in denial of service or potentially the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed in version 2.4.38-3+deb10u7. For the stable distribution (bullseye), these problems have been fixed in version 2.4.52-1~deb11u2. We recommend that you upgrade your apache2 packages. For the detailed security status of apache2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/apache2 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent security issues identified in Apache HTTP server could lead to Denial of Service (DoS) and remote code execution. Debian users should prioritize upgrading their systems.. Apache Security, Debian Update, DoS Risk, Buffer Overflow. . LinuxSecurity.com Team

Calendar%202 Jan 04, 2022 Debian
172

Ubuntu 16.04 ESM USN-5090-4 Critical: Apache HTTP Server Regression Fix

USN-5090-1 introduced a regression in Apache HTTP Server.. =========================================================================Ubuntu Security Notice USN-5090-4 September 28, 2021 apache2 regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: USN-5090-1 introduced a regression in Apache HTTP Server. Software Description: - apache2: Apache HTTP server Details: USN-5090-1 fixed vulnerabilities in Apache HTTP Server. One of the upstream fixes introduced a regression in UDS URIs. This update fixes the problem. Original advisory details: James Kettle discovered that the Apache HTTP Server HTTP/2 module incorrectly handled certain crafted methods. A remote attacker could possibly use this issue to perform request splitting or cache poisoning attacks. (CVE-2021-33193) It was discovered that the Apache HTTP Server incorrectly handled certain malformed requests. A remote attacker could possibly use this issue to cause the server to crash, resulting in a denial of service. (CVE-2021-34798) Li Zhi Xin discovered that the Apache mod_proxy_uwsgi module incorrectly handled certain request uri-paths. A remote attacker could possibly use this issue to cause the server to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS and Ubuntu 21.04. (CVE-2021-36160) It was discovered that the Apache HTTP Server incorrectly handled escaping quotes. If the server was configured with third-party modules, a remote attacker could use this issue to cause the server to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-39275) It was discovered that the Apache mod_proxy module incorrectly handled certain request uri-paths. A remote attacker could possibly use this issue to cause the server to forward requests to arbitrary origin servers. (CVE-2021-40438) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: apache2 2.4.18-2ubuntu3.17+esm3 apache2-bin 2.4.18-2ubuntu3.17+esm3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5090-4 https://ubuntu.com/security/notices/USN-5090-1 . Nginx experienced a vulnerability in Debian 9 that compromises user data and necessitates an immediate patch for resolution.. Apache Update, Ubuntu 16.04, Security Notice, Denial of Service, Request Handling. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 28, 2021 Critical Ubuntu
172

Ubuntu 18.04 LTS USN-4307-1 Critical TLS Support Update

TLSv1.3 support has been enabled in Apache HTTP Server in Ubuntu 18.04 LTS.. =========================================================================Ubuntu Security Notice USN-4307-1 March 18, 2020 apache2 update ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: TLSv1.3 support has been enabled in Apache HTTP Server in Ubuntu 18.04 LTS. Software Description: - apache2: Apache HTTP server Details: As a security improvement, this update adds TLSv1.3 support to the Apache HTTP Server package in Ubuntu 18.04 LTS. TLSv1.3 is enabled by default, and in certain environments may cause compatibility issues. The SSLProtocol directive may be used to disable TLSv1.3 in these problematic environments. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: apache2-bin 2.4.29-1ubuntu4.13 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4307-1 https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/1845263 Package Information: https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.13 . Support for TLSv1.3 has been implemented in the Apache HTTP Server for Ubuntu 20.04 LTS following security advisory USN-4508-1.. apache HTTP, tls support, ubuntu update, apache security, server advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 18, 2020 Critical Ubuntu
98

Important Update RHSA-2019:3933-01 for Red Hat JBoss Core Services HTTP

An update is now available for JBoss Core Services on RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Security Release on RHEL 7 Advisory ID: RHSA-2019:3933-01 Product: Red Hat JBoss Core Services Advisory URL: https://access.redhat.com/errata/RHSA-2019:3933 Issue date: 2019-11-20 CVE Names: CVE-2018-0734 CVE-2018-0737 CVE-2018-5407 CVE-2018-17189 CVE-2018-17199 CVE-2019-0196 CVE-2019-0197 CVE-2019-0217 CVE-2019-9511 CVE-2019-9513 CVE-2019-9516 CVE-2019-9517 ==================================================================== 1. Summary: An update is now available for JBoss Core Services on RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat JBoss Core Services on RHEL 7 Server - noarch, ppc64, x86_64 3. Description: This release adds the new Apache HTTP Server 2.4.37 packages that are part of the JBoss Core Services offering. This release serves as a replacement for Red Hat JBoss Core Services Pack Apache Server 2.4.29 and includes bug fixes and enhancements. Refer to the Release Notes for information on the most significant bug fixes and enhancements included in this release. Security Fix(es): * openssl: RSA key generation cache timing vulnerability in crypto/rsa/rsa_gen.callows attackers to recover private keys (CVE-2018-0737) * openssl: timing side channel attack in the DSA signature algorithm (CVE-2018-0734) * mod_auth_digest: access control bypass due to race condition (CVE-2019-0217) * openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) (CVE-2018-5407) * mod_session_cookie does not respect expiry time (CVE-2018-17199) * mod_http2: DoS via slow, unneeded request bodies (CVE-2018-17189) * mod_http2: possible crash on late upgrade (CVE-2019-0197) * mod_http2: read-after-free on a string compare (CVE-2019-0196) * nghttp2: HTTP/2: large amount of data request leads to denial of service (CVE-2019-9511) * nghttp2: HTTP/2: flood using PRIORITY frames resulting in excessive resource consumption (CVE-2019-9513) * mod_http2: HTTP/2: 0-length headers leads to denial of service (CVE-2019-9516) * mod_http2: HTTP/2: request for large response leads to denial of service (CVE-2019-9517) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. After installing the updated packages, the httpd daemon will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1568253 - CVE-2018-0737 openssl: RSA key generation cache timing vulnerability in crypto/rsa/rsa_gen.c allows attackers to recover private keys 1644364 - CVE-2018-0734 openssl: timing side channel attack in the DSA signature algorithm 1645695 - CVE-2018-5407 openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) 1668493 - CVE-2018-17199 httpd: mod_session_cookie does not respect expiry time 1668497 -CVE-2018-17189 httpd: mod_http2: DoS via slow, unneeded request bodies 1695020 - CVE-2019-0217 httpd: mod_auth_digest: access control bypass due to race condition 1695030 - CVE-2019-0196 httpd: mod_http2: read-after-free on a string compare 1695042 - CVE-2019-0197 httpd: mod_http2: possible crash on late upgrade 1735741 - CVE-2019-9513 HTTP/2: flood using PRIORITY frames results in excessive resource consumption 1741860 - CVE-2019-9511 HTTP/2: large amount of data requests leads to denial of service 1741864 - CVE-2019-9516 HTTP/2: 0-length headers lead to denial of service 1741868 - CVE-2019-9517 HTTP/2: request for large response leads to denial of service 6. Package List: Red Hat JBoss Core Services on RHEL 7Server: Source: jbcs-httpd24-apr-1.6.3-63.jbcs.el7.src.rpm jbcs-httpd24-apr-util-1.6.1-48.jbcs.el7.src.rpm jbcs-httpd24-brotli-1.0.6-7.jbcs.el7.src.rpm jbcs-httpd24-curl-7.64.1-14.jbcs.el7.src.rpm jbcs-httpd24-httpd-2.4.37-33.jbcs.el7.src.rpm jbcs-httpd24-jansson-2.11-20.jbcs.el7.src.rpm jbcs-httpd24-mod_cluster-native-1.3.12-9.Final_redhat_2.jbcs.el7.src.rpm jbcs-httpd24-mod_jk-1.2.46-22.redhat_1.jbcs.el7.src.rpm jbcs-httpd24-mod_security-2.9.2-16.GA.jbcs.el7.src.rpm jbcs-httpd24-nghttp2-1.39.2-4.jbcs.el7.src.rpm jbcs-httpd24-openssl-1.1.1-25.jbcs.el7.src.rpm noarch: jbcs-httpd24-httpd-manual-2.4.37-33.jbcs.el7.noarch.rpm ppc64: jbcs-httpd24-brotli-1.0.6-7.jbcs.el7.ppc64.rpm jbcs-httpd24-brotli-debuginfo-1.0.6-7.jbcs.el7.ppc64.rpm jbcs-httpd24-brotli-devel-1.0.6-7.jbcs.el7.ppc64.rpm jbcs-httpd24-curl-7.64.1-14.jbcs.el7.ppc64.rpm jbcs-httpd24-curl-debuginfo-7.64.1-14.jbcs.el7.ppc64.rpm jbcs-httpd24-httpd-debuginfo-2.4.37-33.jbcs.el7.ppc64.rpm jbcs-httpd24-jansson-2.11-20.jbcs.el7.ppc64.rpm jbcs-httpd24-jansson-debuginfo-2.11-20.jbcs.el7.ppc64.rpm jbcs-httpd24-jansson-devel-2.11-20.jbcs.el7.ppc64.rpm jbcs-httpd24-libcurl-7.64.1-14.jbcs.el7.ppc64.rpm jbcs-httpd24-libcurl-devel-7.64.1-14.jbcs.el7.ppc64.rpm jbcs-httpd24-mod_md-2.4.37-33.jbcs.el7.ppc64.rpm x86_64: jbcs-httpd24-apr-1.6.3-63.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-debuginfo-1.6.3-63.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-devel-1.6.3-63.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-1.6.1-48.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-debuginfo-1.6.1-48.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-devel-1.6.1-48.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-ldap-1.6.1-48.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-mysql-1.6.1-48.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-nss-1.6.1-48.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-odbc-1.6.1-48.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-openssl-1.6.1-48.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-pgsql-1.6.1-48.jbcs.el7.x86_64.rpm jbcs-httpd24-apr-util-sqlite-1.6.1-48.jbcs.el7.x86_64.rpm jbcs-httpd24-brotli-1.0.6-7.jbcs.el7.x86_64.rpm jbcs-httpd24-brotli-debuginfo-1.0.6-7.jbcs.el7.x86_64.rpm jbcs-httpd24-brotli-devel-1.0.6-7.jbcs.el7.x86_64.rpm jbcs-httpd24-curl-7.64.1-14.jbcs.el7.x86_64.rpm jbcs-httpd24-curl-debuginfo-7.64.1-14.jbcs.el7.x86_64.rpm jbcs-httpd24-httpd-2.4.37-33.jbcs.el7.x86_64.rpm jbcs-httpd24-httpd-debuginfo-2.4.37-33.jbcs.el7.x86_64.rpm jbcs-httpd24-httpd-devel-2.4.37-33.jbcs.el7.x86_64.rpm jbcs-httpd24-httpd-selinux-2.4.37-33.jbcs.el7.x86_64.rpm jbcs-httpd24-httpd-tools-2.4.37-33.jbcs.el7.x86_64.rpm jbcs-httpd24-jansson-2.11-20.jbcs.el7.x86_64.rpm jbcs-httpd24-jansson-debuginfo-2.11-20.jbcs.el7.x86_64.rpm jbcs-httpd24-jansson-devel-2.11-20.jbcs.el7.x86_64.rpm jbcs-httpd24-libcurl-7.64.1-14.jbcs.el7.x86_64.rpm jbcs-httpd24-libcurl-devel-7.64.1-14.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_cluster-native-1.3.12-9.Final_redhat_2.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_cluster-native-debuginfo-1.3.12-9.Final_redhat_2.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_jk-ap24-1.2.46-22.redhat_1.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_jk-debuginfo-1.2.46-22.redhat_1.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_jk-manual-1.2.46-22.redhat_1.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_ldap-2.4.37-33.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_md-2.4.37-33.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_proxy_html-2.4.37-33.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_security-2.9.2-16.GA.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_security-debuginfo-2.9.2-16.GA.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_session-2.4.37-33.jbcs.el7.x86_64.rpm jbcs-httpd24-mod_ssl-2.4.37-33.jbcs.el7.x86_64.rpm jbcs-httpd24-nghttp2-1.39.2-4.jbcs.el7.x86_64.rpm jbcs-httpd24-nghttp2-debuginfo-1.39.2-4.jbcs.el7.x86_64.rpm jbcs-httpd24-nghttp2-devel-1.39.2-4.jbcs.el7.x86_64.rpm jbcs-httpd24-openssl-1.1.1-25.jbcs.el7.x86_64.rpm jbcs-httpd24-openssl-debuginfo-1.1.1-25.jbcs.el7.x86_64.rpm jbcs-httpd24-openssl-devel-1.1.1-25.jbcs.el7.x86_64.rpm jbcs-httpd24-openssl-libs-1.1.1-25.jbcs.el7.x86_64.rpm jbcs-httpd24-openssl-perl-1.1.1-25.jbcs.el7.x86_64.rpm jbcs-httpd24-openssl-static-1.1.1-25.jbcs.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-0734 https://access.redhat.com/security/cve/CVE-2018-0737 https://access.redhat.com/security/cve/CVE-2018-5407 https://access.redhat.com/security/cve/CVE-2018-17189 https://access.redhat.com/security/cve/CVE-2018-17199 https://access.redhat.com/security/cve/CVE-2019-0196 https://access.redhat.com/security/cve/CVE-2019-0197 https://access.redhat.com/security/cve/CVE-2019-0217 https://access.redhat.com/security/cve/CVE-2019-9511 https://access.redhat.com/security/cve/CVE-2019-9513 https://access.redhat.com/security/cve/CVE-2019-9516 https://access.redhat.com/security/cve/CVE-2019-9517 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE-----Version: GnuPG v1 iQIVAwUBXdVmUNzjgjWX9erEAQgHaA/5ATJ1vNONW5SjAljtzRcgd0M7yegmqkML /+Fau+KCMjV6qEz5Hd79mubu+uf405EXfuJdi0Da5vbBVEK9PY5H+46Ea5BozqJE mgPIulbir54fQkWV/8eltCF7GRcs1k+DRa8NLGyXZxAcgKXxy4vAx00tjPEwPAZw CLPHLujYehq5Wty83gvnST8Set3n2f0eREbLpFMMIUZDErGlh6PZs1I1Id1BaBDF SAAiZeWmwF3jOTknmkZc8m+dnFrn80hF5O5QwadlNgn2FmheT365hW+443z5RTlM bL+pboWM9mmd9NAHse0lwW2IARA5Vr593qbbMwOGXrt9PEhivpRcMbbKb7JMEJQY 6HM+Eo/5vPzA4iR+c5OzdsF3fSYdigR7duUNU40QZbP+++RyaCYSxLM9XSfDe9v/ YQi7TgZ/iv9vilMtNvHsrLzgpj7ltLl3Qk6HB+2zBLJOivf/Quji1efEFE59bfkS TJ4pCLc7JA1dN5Xg4+xyn8d60JVG/w+ZloPLYegXL4yU8mb0Fz/3AFS99kEsok6U hq5p3/qWJmM0MMFmwPVAM6nIYPJai6xKmGzN2d42LG7bTFhAEGFQuvrnSWm49b3Q 4TaV/VN89NjpxXxB4mn0eK4lCtndEYGTXnIZTRv1ju60Zsoz+YcQf/Xy/236CvnK TbHYaKmVCfE=6pM8 -----END PGP SIGNATURE-------RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Update available for Red HatJBoss Core Services addressing important security issues with Apache HTTP.. update, jboss, services, product, security, rated. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 20, 2019 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200