RHSA-2016:1648: Important: Red Hat JBoss Web Server 2.1.1 security update on RHEL 7

Published Aug 22, 2016
·
Updated

Red Hat JBoss Web Server is a fully integrated and certified set ofcomponents for hosting Java web applications. It is comprised of the ApacheHTTP Server, the Apache Tomcat Servlet container, Apache Tomcat Connector(modjk), JBoss HTTP Connector (modcluster), Hibernate, and the TomcatNative library.This release serves as a replacement for Red Hat JBoss Web Server 2.1.0,and includes several bug fixes. Refer to the Red Hat JBoss Web Server 2.1.1Release Notes for information on the most significant of these changes,available shortly from https://access.redhat.com/site/documentation/ All users of Red Hat JBoss Web Server 2.1.0 on Red Hat Enterprise Linux 7are advised to upgrade to Red Hat JBoss Web Server 2.1.1. The JBoss serverprocess must be restarted for this update to take effect.Security Fix(es): It was discovered that httpd used the value of the Proxy header from HTTP requests to initialize the HTTPPROXY environment variable for CGI scripts,which in turn was incorrectly used by certain HTTP client implementationsto configure the proxy for outgoing HTTP requests. A remote attacker couldpossibly use this flaw to redirect HTTP requests performed by a CGI scriptto an attacker-controlled proxy via a malicious HTTP request.(CVE-2016-5387) An integer overflow flaw, leading to a buffer overflow, was found in the way the EVPEncodeUpdate() function of OpenSSL parsed very large amounts ofinput data. A remote attacker could use this flaw to crash an applicationusing OpenSSL or, possibly, execute arbitrary code with the permissions ofthe user running that application. (CVE-2016-2105) An integer overflow flaw, leading to a buffer overflow, was found in the way the EVPEncryptUpdate() function of OpenSSL parsed very large amountsof input data. A remote attacker could use this flaw to crash anapplication using OpenSSL or, possibly, execute arbitrary code with thepermissions of the user running that application. (CVE-2016-2106) It was discovered that it is possible to remotely Segfault Apache http server with a specially crafted string sent to the modcluster via servicemessages (MCMP). (CVE-2016-3110)Red Hat would like to thank Scott Geary (VendHQ) for reportingCVE-2016-5387; the OpenSSL project for reporting CVE-2016-2105 andCVE-2016-2106; and Michal Karm Babacek for reporting CVE-2016-3110.Upstream acknowledges Guido Vranken as the original reporter ofCVE-2016-2105 and CVE-2016-2106.

Affected Software

18 affected componentsFixes available
redhat/httpd22<2.2.26-56.ep6.el7
2.2.26-56.ep6.el7
redhat/jbcs-httpd24-openssl<1.0.2h-4.jbcs.el7
1.0.2h-4.jbcs.el7
redhat/tomcat-native<1.1.34-5.redhat_1.ep6.el7
1.1.34-5.redhat_1.ep6.el7
redhat/httpd22<2.2.26-56.ep6.el7
2.2.26-56.ep6.el7
redhat/httpd22-debuginfo<2.2.26-56.ep6.el7
2.2.26-56.ep6.el7
redhat/httpd22-devel<2.2.26-56.ep6.el7
2.2.26-56.ep6.el7
redhat/httpd22-manual<2.2.26-56.ep6.el7
2.2.26-56.ep6.el7
redhat/httpd22-tools<2.2.26-56.ep6.el7
2.2.26-56.ep6.el7
redhat/jbcs-httpd24<1-3.jbcs.el7
1-3.jbcs.el7
redhat/jbcs-httpd24-openssl<1.0.2h-4.jbcs.el7
1.0.2h-4.jbcs.el7
redhat/jbcs-httpd24-openssl-debuginfo<1.0.2h-4.jbcs.el7
1.0.2h-4.jbcs.el7
redhat/jbcs-httpd24-openssl-devel<1.0.2h-4.jbcs.el7
1.0.2h-4.jbcs.el7
redhat/jbcs-httpd24-openssl-libs<1.0.2h-4.jbcs.el7
1.0.2h-4.jbcs.el7
redhat/jbcs-httpd24-openssl-perl<1.0.2h-4.jbcs.el7
1.0.2h-4.jbcs.el7
redhat/jbcs-httpd24-openssl-static<1.0.2h-4.jbcs.el7
1.0.2h-4.jbcs.el7
redhat/jbcs-httpd24-runtime<1-3.jbcs.el7
1-3.jbcs.el7
redhat/tomcat-native<1.1.34-5.redhat_1.ep6.el7
1.1.34-5.redhat_1.ep6.el7
redhat/tomcat-native-debuginfo<1.1.34-5.redhat_1.ep6.el7
1.1.34-5.redhat_1.ep6.el7

Remediation

Event History

Aug 22, 2016
Advisory Published
12:00 AM

Frequently Asked Questions

1

What is the severity of RHSA-2016:1648?

The severity of RHSA-2016:1648 is classified as important.

2

How do I fix RHSA-2016:1648?

To fix RHSA-2016:1648, update the affected packages to the specified remedied versions provided in the advisory.

3

Which packages are affected by RHSA-2016:1648?

The affected packages include httpd22, jbcs-httpd24-openssl, and tomcat-native among others.

4

What systems are impacted by RHSA-2016:1648?

RHSA-2016:1648 impacts systems using Red Hat JBoss Web Server integrated with Apache HTTP Server and Tomcat.

5

Is there a workaround for RHSA-2016:1648?

No specific workaround is suggested for RHSA-2016:1648; applying the update is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203