RHSA-2017:2493: Important: Red Hat JBoss Web Server 2 security update

Published Aug 21, 2017
·
Updated

OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.This release provides an update to OpenSSL and Tomcat 6/7 for Red Hat JBoss Web Server 2.1.2. The updates are documented in the Release Notes document linked to in the References.Users of Red Hat JBoss Web Server 2.1.2 should upgrade to these updated packages, which resolve several security issues.Security Fix(es): A memory leak flaw was found in the way OpenSSL handled TLS status request extension data during session renegotiation. A remote attacker could cause a TLS server using OpenSSL to consume an excessive amount of memory and, possibly, exit unexpectedly after exhausting all available memory, if it enabled OCSP stapling support. (CVE-2016-6304) A vulnerability was discovered in tomcat's handling of pipelined requests when "Sendfile" was used. If sendfile processing completed quickly, it was possible for the Processor to be added to the processor cache twice. This could lead to invalid responses or information disclosure. (CVE-2017-5647) A vulnerability was discovered in the error page mechanism in Tomcat's DefaultServlet implementation. A crafted HTTP request could cause undesired side effects, possibly including the removal or replacement of the custom error page. (CVE-2017-5664) A denial of service flaw was found in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients. (CVE-2016-8610) Red Hat would like to thank the OpenSSL project for reporting CVE-2016-6304 and Shi Lei (Gear Team of Qihoo 360 Inc.) for reporting CVE-2016-8610. Upstream acknowledges Shi Lei (Gear Team of Qihoo 360 Inc.) as the original reporter of CVE-2016-6304.

Affected Software

67 affected componentsFixes available
redhat/jbcs-httpd24-openssl<1.0.2h-13.jbcs.el7
1.0.2h-13.jbcs.el7
redhat/tomcat6<6.0.41-17_patch_04.ep6.el7
6.0.41-17_patch_04.ep6.el7
redhat/tomcat7<7.0.54-25_patch_05.ep6.el7
7.0.54-25_patch_05.ep6.el7
redhat/jbcs-httpd24-openssl<1.0.2h-13.jbcs.el7
1.0.2h-13.jbcs.el7
redhat/jbcs-httpd24-openssl-debuginfo<1.0.2h-13.jbcs.el7
1.0.2h-13.jbcs.el7
redhat/jbcs-httpd24-openssl-devel<1.0.2h-13.jbcs.el7
1.0.2h-13.jbcs.el7
redhat/jbcs-httpd24-openssl-libs<1.0.2h-13.jbcs.el7
1.0.2h-13.jbcs.el7
redhat/jbcs-httpd24-openssl-perl<1.0.2h-13.jbcs.el7
1.0.2h-13.jbcs.el7
redhat/jbcs-httpd24-openssl-static<1.0.2h-13.jbcs.el7
1.0.2h-13.jbcs.el7
redhat/tomcat6<6.0.41-17_patch_04.ep6.el7
6.0.41-17_patch_04.ep6.el7
redhat/tomcat6-admin-webapps<6.0.41-17_patch_04.ep6.el7
6.0.41-17_patch_04.ep6.el7
redhat/tomcat6-docs-webapp<6.0.41-17_patch_04.ep6.el7
6.0.41-17_patch_04.ep6.el7
redhat/tomcat6-el<2.1-api-6.0.41-17_patch_04.ep6.el7
2.1-api-6.0.41-17_patch_04.ep6.el7
redhat/tomcat6-javadoc<6.0.41-17_patch_04.ep6.el7
6.0.41-17_patch_04.ep6.el7
redhat/tomcat6-jsp<2.1-api-6.0.41-17_patch_04.ep6.el7
2.1-api-6.0.41-17_patch_04.ep6.el7
redhat/tomcat6-lib<6.0.41-17_patch_04.ep6.el7
6.0.41-17_patch_04.ep6.el7
redhat/tomcat6-log4j<6.0.41-17_patch_04.ep6.el7
6.0.41-17_patch_04.ep6.el7
redhat/tomcat6-maven-devel<6.0.41-17_patch_04.ep6.el7
6.0.41-17_patch_04.ep6.el7
redhat/tomcat6-servlet<2.5-api-6.0.41-17_patch_04.ep6.el7
2.5-api-6.0.41-17_patch_04.ep6.el7
redhat/tomcat6-webapps<6.0.41-17_patch_04.ep6.el7
6.0.41-17_patch_04.ep6.el7
redhat/tomcat7<7.0.54-25_patch_05.ep6.el7
7.0.54-25_patch_05.ep6.el7
redhat/tomcat7-admin-webapps<7.0.54-25_patch_05.ep6.el7
7.0.54-25_patch_05.ep6.el7
redhat/tomcat7-docs-webapp<7.0.54-25_patch_05.ep6.el7
7.0.54-25_patch_05.ep6.el7
redhat/tomcat7-el<2.2-api-7.0.54-25_patch_05.ep6.el7
2.2-api-7.0.54-25_patch_05.ep6.el7
redhat/tomcat7-javadoc<7.0.54-25_patch_05.ep6.el7
7.0.54-25_patch_05.ep6.el7
redhat/tomcat7-jsp<2.2-api-7.0.54-25_patch_05.ep6.el7
2.2-api-7.0.54-25_patch_05.ep6.el7
redhat/tomcat7-lib<7.0.54-25_patch_05.ep6.el7
7.0.54-25_patch_05.ep6.el7
redhat/tomcat7-log4j<7.0.54-25_patch_05.ep6.el7
7.0.54-25_patch_05.ep6.el7
redhat/tomcat7-maven-devel<7.0.54-25_patch_05.ep6.el7
7.0.54-25_patch_05.ep6.el7
redhat/tomcat7-servlet<3.0-api-7.0.54-25_patch_05.ep6.el7
3.0-api-7.0.54-25_patch_05.ep6.el7
redhat/tomcat7-webapps<7.0.54-25_patch_05.ep6.el7
7.0.54-25_patch_05.ep6.el7
redhat/jbcs-httpd24-openssl<1.0.2h-13.jbcs.el6
1.0.2h-13.jbcs.el6
redhat/tomcat6<6.0.41-17_patch_04.ep6.el6
6.0.41-17_patch_04.ep6.el6
redhat/tomcat7<7.0.54-25_patch_05.ep6.el6
7.0.54-25_patch_05.ep6.el6
redhat/jbcs-httpd24-openssl<1.0.2h-13.jbcs.el6
1.0.2h-13.jbcs.el6
redhat/jbcs-httpd24-openssl-debuginfo<1.0.2h-13.jbcs.el6
1.0.2h-13.jbcs.el6
redhat/jbcs-httpd24-openssl-devel<1.0.2h-13.jbcs.el6
1.0.2h-13.jbcs.el6
redhat/jbcs-httpd24-openssl-libs<1.0.2h-13.jbcs.el6
1.0.2h-13.jbcs.el6
redhat/jbcs-httpd24-openssl-perl<1.0.2h-13.jbcs.el6
1.0.2h-13.jbcs.el6
redhat/jbcs-httpd24-openssl-static<1.0.2h-13.jbcs.el6
1.0.2h-13.jbcs.el6
redhat/tomcat6<6.0.41-17_patch_04.ep6.el6
6.0.41-17_patch_04.ep6.el6
redhat/tomcat6-admin-webapps<6.0.41-17_patch_04.ep6.el6
6.0.41-17_patch_04.ep6.el6
redhat/tomcat6-docs-webapp<6.0.41-17_patch_04.ep6.el6
6.0.41-17_patch_04.ep6.el6
redhat/tomcat6-el<2.1-api-6.0.41-17_patch_04.ep6.el6
2.1-api-6.0.41-17_patch_04.ep6.el6
redhat/tomcat6-javadoc<6.0.41-17_patch_04.ep6.el6
6.0.41-17_patch_04.ep6.el6
redhat/tomcat6-jsp<2.1-api-6.0.41-17_patch_04.ep6.el6
2.1-api-6.0.41-17_patch_04.ep6.el6
redhat/tomcat6-lib<6.0.41-17_patch_04.ep6.el6
6.0.41-17_patch_04.ep6.el6
redhat/tomcat6-log4j<6.0.41-17_patch_04.ep6.el6
6.0.41-17_patch_04.ep6.el6
redhat/tomcat6-maven-devel<6.0.41-17_patch_04.ep6.el6
6.0.41-17_patch_04.ep6.el6
redhat/tomcat6-servlet<2.5-api-6.0.41-17_patch_04.ep6.el6
2.5-api-6.0.41-17_patch_04.ep6.el6
redhat/tomcat6-webapps<6.0.41-17_patch_04.ep6.el6
6.0.41-17_patch_04.ep6.el6
redhat/tomcat7<7.0.54-25_patch_05.ep6.el6
7.0.54-25_patch_05.ep6.el6
redhat/tomcat7-admin-webapps<7.0.54-25_patch_05.ep6.el6
7.0.54-25_patch_05.ep6.el6
redhat/tomcat7-docs-webapp<7.0.54-25_patch_05.ep6.el6
7.0.54-25_patch_05.ep6.el6
redhat/tomcat7-el<2.2-api-7.0.54-25_patch_05.ep6.el6
2.2-api-7.0.54-25_patch_05.ep6.el6
redhat/tomcat7-javadoc<7.0.54-25_patch_05.ep6.el6
7.0.54-25_patch_05.ep6.el6
redhat/tomcat7-jsp<2.2-api-7.0.54-25_patch_05.ep6.el6
2.2-api-7.0.54-25_patch_05.ep6.el6
redhat/tomcat7-lib<7.0.54-25_patch_05.ep6.el6
7.0.54-25_patch_05.ep6.el6
redhat/tomcat7-log4j<7.0.54-25_patch_05.ep6.el6
7.0.54-25_patch_05.ep6.el6
redhat/tomcat7-maven-devel<7.0.54-25_patch_05.ep6.el6
7.0.54-25_patch_05.ep6.el6
redhat/tomcat7-servlet<3.0-api-7.0.54-25_patch_05.ep6.el6
3.0-api-7.0.54-25_patch_05.ep6.el6
redhat/tomcat7-webapps<7.0.54-25_patch_05.ep6.el6
7.0.54-25_patch_05.ep6.el6
redhat/jbcs-httpd24-openssl-debuginfo<1.0.2h-13.jbcs.el6
1.0.2h-13.jbcs.el6
redhat/jbcs-httpd24-openssl-devel<1.0.2h-13.jbcs.el6
1.0.2h-13.jbcs.el6
redhat/jbcs-httpd24-openssl-libs<1.0.2h-13.jbcs.el6
1.0.2h-13.jbcs.el6
redhat/jbcs-httpd24-openssl-perl<1.0.2h-13.jbcs.el6
1.0.2h-13.jbcs.el6
redhat/jbcs-httpd24-openssl-static<1.0.2h-13.jbcs.el6
1.0.2h-13.jbcs.el6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl to a version that resolves this vulnerability.

    Fixed in 1.0.2h-13.jbcs.el7
  2. Upgrade

    Upgrade redhat/tomcat6 to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el7
  3. Upgrade

    Upgrade redhat/tomcat7 to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el7
  4. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl-debuginfo to a version that resolves this vulnerability.

    Fixed in 1.0.2h-13.jbcs.el7
  5. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl-devel to a version that resolves this vulnerability.

    Fixed in 1.0.2h-13.jbcs.el7
  6. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl-libs to a version that resolves this vulnerability.

    Fixed in 1.0.2h-13.jbcs.el7
  7. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl-perl to a version that resolves this vulnerability.

    Fixed in 1.0.2h-13.jbcs.el7
  8. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl-static to a version that resolves this vulnerability.

    Fixed in 1.0.2h-13.jbcs.el7
  9. Upgrade

    Upgrade redhat/tomcat6-admin-webapps to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el7
  10. Upgrade

    Upgrade redhat/tomcat6-docs-webapp to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el7
  11. Upgrade

    Upgrade redhat/tomcat6-el to a version that resolves this vulnerability.

    Fixed in 2.1-api-6.0.41-17_patch_04.ep6.el7
  12. Upgrade

    Upgrade redhat/tomcat6-javadoc to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el7
  13. Upgrade

    Upgrade redhat/tomcat6-jsp to a version that resolves this vulnerability.

    Fixed in 2.1-api-6.0.41-17_patch_04.ep6.el7
  14. Upgrade

    Upgrade redhat/tomcat6-lib to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el7
  15. Upgrade

    Upgrade redhat/tomcat6-log4j to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el7
  16. Upgrade

    Upgrade redhat/tomcat6-maven-devel to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el7
  17. Upgrade

    Upgrade redhat/tomcat6-servlet to a version that resolves this vulnerability.

    Fixed in 2.5-api-6.0.41-17_patch_04.ep6.el7
  18. Upgrade

    Upgrade redhat/tomcat6-webapps to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el7
  19. Upgrade

    Upgrade redhat/tomcat7-admin-webapps to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el7
  20. Upgrade

    Upgrade redhat/tomcat7-docs-webapp to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el7
  21. Upgrade

    Upgrade redhat/tomcat7-el to a version that resolves this vulnerability.

    Fixed in 2.2-api-7.0.54-25_patch_05.ep6.el7
  22. Upgrade

    Upgrade redhat/tomcat7-javadoc to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el7
  23. Upgrade

    Upgrade redhat/tomcat7-jsp to a version that resolves this vulnerability.

    Fixed in 2.2-api-7.0.54-25_patch_05.ep6.el7
  24. Upgrade

    Upgrade redhat/tomcat7-lib to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el7
  25. Upgrade

    Upgrade redhat/tomcat7-log4j to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el7
  26. Upgrade

    Upgrade redhat/tomcat7-maven-devel to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el7
  27. Upgrade

    Upgrade redhat/tomcat7-servlet to a version that resolves this vulnerability.

    Fixed in 3.0-api-7.0.54-25_patch_05.ep6.el7
  28. Upgrade

    Upgrade redhat/tomcat7-webapps to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el7
  29. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl to a version that resolves this vulnerability.

    Fixed in 1.0.2h-13.jbcs.el6
  30. Upgrade

    Upgrade redhat/tomcat6 to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el6
  31. Upgrade

    Upgrade redhat/tomcat7 to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el6
  32. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl-debuginfo to a version that resolves this vulnerability.

    Fixed in 1.0.2h-13.jbcs.el6
  33. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl-devel to a version that resolves this vulnerability.

    Fixed in 1.0.2h-13.jbcs.el6
  34. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl-libs to a version that resolves this vulnerability.

    Fixed in 1.0.2h-13.jbcs.el6
  35. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl-perl to a version that resolves this vulnerability.

    Fixed in 1.0.2h-13.jbcs.el6
  36. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl-static to a version that resolves this vulnerability.

    Fixed in 1.0.2h-13.jbcs.el6
  37. Upgrade

    Upgrade redhat/tomcat6-admin-webapps to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el6
  38. Upgrade

    Upgrade redhat/tomcat6-docs-webapp to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el6
  39. Upgrade

    Upgrade redhat/tomcat6-el to a version that resolves this vulnerability.

    Fixed in 2.1-api-6.0.41-17_patch_04.ep6.el6
  40. Upgrade

    Upgrade redhat/tomcat6-javadoc to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el6
  41. Upgrade

    Upgrade redhat/tomcat6-jsp to a version that resolves this vulnerability.

    Fixed in 2.1-api-6.0.41-17_patch_04.ep6.el6
  42. Upgrade

    Upgrade redhat/tomcat6-lib to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el6
  43. Upgrade

    Upgrade redhat/tomcat6-log4j to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el6
  44. Upgrade

    Upgrade redhat/tomcat6-maven-devel to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el6
  45. Upgrade

    Upgrade redhat/tomcat6-servlet to a version that resolves this vulnerability.

    Fixed in 2.5-api-6.0.41-17_patch_04.ep6.el6
  46. Upgrade

    Upgrade redhat/tomcat6-webapps to a version that resolves this vulnerability.

    Fixed in 6.0.41-17_patch_04.ep6.el6
  47. Upgrade

    Upgrade redhat/tomcat7-admin-webapps to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el6
  48. Upgrade

    Upgrade redhat/tomcat7-docs-webapp to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el6
  49. Upgrade

    Upgrade redhat/tomcat7-el to a version that resolves this vulnerability.

    Fixed in 2.2-api-7.0.54-25_patch_05.ep6.el6
  50. Upgrade

    Upgrade redhat/tomcat7-javadoc to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el6
  51. Upgrade

    Upgrade redhat/tomcat7-jsp to a version that resolves this vulnerability.

    Fixed in 2.2-api-7.0.54-25_patch_05.ep6.el6
  52. Upgrade

    Upgrade redhat/tomcat7-lib to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el6
  53. Upgrade

    Upgrade redhat/tomcat7-log4j to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el6
  54. Upgrade

    Upgrade redhat/tomcat7-maven-devel to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el6
  55. Upgrade

    Upgrade redhat/tomcat7-servlet to a version that resolves this vulnerability.

    Fixed in 3.0-api-7.0.54-25_patch_05.ep6.el6
  56. Upgrade

    Upgrade redhat/tomcat7-webapps to a version that resolves this vulnerability.

    Fixed in 7.0.54-25_patch_05.ep6.el6

Event History

Aug 5, 2026
Advisory Published
via Red Hat·10:56 AM
Data Sourced
via Red Hat·10:56 AM
RemedyDescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2017:2493?

RHSA-2017:2493 is classified as a critical vulnerability affecting OpenSSL and Apache Tomcat.

2

How do I fix RHSA-2017:2493?

To fix RHSA-2017:2493, update your installation of OpenSSL to version 1.0.2h-13.jbcs.el7 or update Tomcat to versions 6.0.41-17_patch_04.ep6.el7 or 7.0.54-25_patch_05.ep6.el7.

3

What packages are affected by RHSA-2017:2493?

RHSA-2017:2493 affects the jbcs-httpd24-openssl, tomcat6, and tomcat7 packages among others.

4

When was RHSA-2017:2493 issued?

RHSA-2017:2493 was issued on October 25, 2017.

5

Is RHSA-2017:2493 relevant for older systems?

Yes, RHSA-2017:2493 remains relevant for older systems still running affected versions of the software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203