First published: Mon Jun 22 2020(Updated: )
This release adds the new Apache HTTP Server 2.4.37 Service Pack 3 packages that are part of the JBoss Core Services offering.<br>This release serves as a replacement for Red Hat JBoss Core Services Pack Apache Server 2.4.37 Service Pack 2 and includes bug fixes and enhancements. Refer to the Release Notes for information on the most significant bug fixes and enhancements included in this release.<br>Security fix(es):<br><li> httpd: mod_http2: read-after-free on a string compare (CVE-2019-0196)</li> <li> httpd: mod_http2: possible crash on late upgrade (CVE-2019-0197)</li> <li> httpd: mod_proxy_ftp use of uninitialized value (CVE-2020-1934)</li> <li> nghttp2: overly large SETTINGS frames can lead to DoS (CVE-2020-11080)</li> <li> libxml2: There's a memory leak in xmlParseBalancedChunkMemoryRecover in parser.c that could result in a crash (CVE-2019-19956)</li> <li> libxml2: memory leak in xmlSchemaPreRun in xmlschemas.c (CVE-2019-20388)</li> <li> libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations (CVE-2020-7595)</li> <li> expat: large number of colons in input makes parser consume high amount of resources, leading to DoS (CVE-2018-20843)</li> <li> expat: heap-based buffer over-read via crafted XML input (CVE-2019-15903)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jbcs-httpd24-curl | <7.64.1-36.jbcs.el7 | 7.64.1-36.jbcs.el7 |
redhat/jbcs-httpd24-httpd | <2.4.37-57.jbcs.el7 | 2.4.37-57.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2 | <1.39.2-25.jbcs.el7 | 1.39.2-25.jbcs.el7 |
redhat/jbcs-httpd24-openssl-pkcs11 | <0.4.10-7.jbcs.el7 | 0.4.10-7.jbcs.el7 |
redhat/jbcs-httpd24-curl | <7.64.1-36.jbcs.el7 | 7.64.1-36.jbcs.el7 |
redhat/jbcs-httpd24-curl-debuginfo | <7.64.1-36.jbcs.el7 | 7.64.1-36.jbcs.el7 |
redhat/jbcs-httpd24-httpd | <2.4.37-57.jbcs.el7 | 2.4.37-57.jbcs.el7 |
redhat/jbcs-httpd24-httpd-debuginfo | <2.4.37-57.jbcs.el7 | 2.4.37-57.jbcs.el7 |
redhat/jbcs-httpd24-httpd-devel | <2.4.37-57.jbcs.el7 | 2.4.37-57.jbcs.el7 |
redhat/jbcs-httpd24-httpd-manual | <2.4.37-57.jbcs.el7 | 2.4.37-57.jbcs.el7 |
redhat/jbcs-httpd24-httpd-selinux | <2.4.37-57.jbcs.el7 | 2.4.37-57.jbcs.el7 |
redhat/jbcs-httpd24-httpd-tools | <2.4.37-57.jbcs.el7 | 2.4.37-57.jbcs.el7 |
redhat/jbcs-httpd24-libcurl | <7.64.1-36.jbcs.el7 | 7.64.1-36.jbcs.el7 |
redhat/jbcs-httpd24-libcurl-devel | <7.64.1-36.jbcs.el7 | 7.64.1-36.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2 | <1.39.2-25.jbcs.el7 | 1.39.2-25.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2-debuginfo | <1.39.2-25.jbcs.el7 | 1.39.2-25.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2-devel | <1.39.2-25.jbcs.el7 | 1.39.2-25.jbcs.el7 |
redhat/jbcs-httpd24-openssl-pkcs11 | <0.4.10-7.jbcs.el7 | 0.4.10-7.jbcs.el7 |
redhat/jbcs-httpd24-openssl-pkcs11-debuginfo | <0.4.10-7.jbcs.el7 | 0.4.10-7.jbcs.el7 |
redhat/jbcs-httpd24-curl | <7.64.1-36.jbcs.el6 | 7.64.1-36.jbcs.el6 |
redhat/jbcs-httpd24-httpd | <2.4.37-57.jbcs.el6 | 2.4.37-57.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2 | <1.39.2-25.jbcs.el6 | 1.39.2-25.jbcs.el6 |
redhat/jbcs-httpd24-curl | <7.64.1-36.jbcs.el6 | 7.64.1-36.jbcs.el6 |
redhat/jbcs-httpd24-curl-debuginfo | <7.64.1-36.jbcs.el6 | 7.64.1-36.jbcs.el6 |
redhat/jbcs-httpd24-httpd | <2.4.37-57.jbcs.el6 | 2.4.37-57.jbcs.el6 |
redhat/jbcs-httpd24-httpd-debuginfo | <2.4.37-57.jbcs.el6 | 2.4.37-57.jbcs.el6 |
redhat/jbcs-httpd24-httpd-devel | <2.4.37-57.jbcs.el6 | 2.4.37-57.jbcs.el6 |
redhat/jbcs-httpd24-httpd-manual | <2.4.37-57.jbcs.el6 | 2.4.37-57.jbcs.el6 |
redhat/jbcs-httpd24-httpd-selinux | <2.4.37-57.jbcs.el6 | 2.4.37-57.jbcs.el6 |
redhat/jbcs-httpd24-httpd-tools | <2.4.37-57.jbcs.el6 | 2.4.37-57.jbcs.el6 |
redhat/jbcs-httpd24-libcurl | <7.64.1-36.jbcs.el6 | 7.64.1-36.jbcs.el6 |
redhat/jbcs-httpd24-libcurl-devel | <7.64.1-36.jbcs.el6 | 7.64.1-36.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2 | <1.39.2-25.jbcs.el6 | 1.39.2-25.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2-debuginfo | <1.39.2-25.jbcs.el6 | 1.39.2-25.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2-devel | <1.39.2-25.jbcs.el6 | 1.39.2-25.jbcs.el6 |
redhat/jbcs-httpd24-curl-debuginfo | <7.64.1-36.jbcs.el6 | 7.64.1-36.jbcs.el6 |
redhat/jbcs-httpd24-httpd-debuginfo | <2.4.37-57.jbcs.el6 | 2.4.37-57.jbcs.el6 |
redhat/jbcs-httpd24-httpd-devel | <2.4.37-57.jbcs.el6 | 2.4.37-57.jbcs.el6 |
redhat/jbcs-httpd24-httpd-selinux | <2.4.37-57.jbcs.el6 | 2.4.37-57.jbcs.el6 |
redhat/jbcs-httpd24-httpd-tools | <2.4.37-57.jbcs.el6 | 2.4.37-57.jbcs.el6 |
redhat/jbcs-httpd24-libcurl | <7.64.1-36.jbcs.el6 | 7.64.1-36.jbcs.el6 |
redhat/jbcs-httpd24-libcurl-devel | <7.64.1-36.jbcs.el6 | 7.64.1-36.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2-debuginfo | <1.39.2-25.jbcs.el6 | 1.39.2-25.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2-devel | <1.39.2-25.jbcs.el6 | 1.39.2-25.jbcs.el6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.