First published: Wed Oct 28 2020(Updated: )
This release adds the new Apache HTTP Server 2.4.37 Service Pack 5 packages that are part of the JBoss Core Services offering.<br>This release serves as a replacement for Red Hat JBoss Core Services Pack Apache Server 2.4.37 Service Pack 3 and includes bug fixes and enhancements. Refer to the Release Notes for information on the most significant bug fixes and enhancements included in this release.<br>Security fix(es):<br><li> curl: Integer overflows in curl_url_set() function (CVE-2019-5435)</li> <li> openssl: Integer overflow in RSAZ modular exponentiation on x86_64 (CVE-2019-1551)</li> <li> httpd: mod_http2 concurrent pool usage (CVE-2020-11993)</li> <li> httpd: mod_proxy_uswgi buffer overflow (CVE-2020-11984)</li> <li> httpd: allow connecting via SSL to a backend worker when the backend keystore file's ID is 'unknown' (CVE-2020-25680)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jbcs-httpd24-apr | <1.6.3-104.jbcs.el7 | 1.6.3-104.jbcs.el7 |
redhat/jbcs-httpd24-apr-util | <1.6.1-75.jbcs.el7 | 1.6.1-75.jbcs.el7 |
redhat/jbcs-httpd24-brotli | <1.0.6-38.jbcs.el7 | 1.0.6-38.jbcs.el7 |
redhat/jbcs-httpd24-curl | <7.64.1-44.jbcs.el7 | 7.64.1-44.jbcs.el7 |
redhat/jbcs-httpd24-httpd | <2.4.37-64.jbcs.el7 | 2.4.37-64.jbcs.el7 |
redhat/jbcs-httpd24-jansson | <2.11-53.jbcs.el7 | 2.11-53.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2 | <1.39.2-34.jbcs.el7 | 1.39.2-34.jbcs.el7 |
redhat/jbcs-httpd24-openssl | <1.1.1c-32.jbcs.el7 | 1.1.1c-32.jbcs.el7 |
redhat/jbcs-httpd24-openssl-chil | <1.0.0-1.jbcs.el7 | 1.0.0-1.jbcs.el7 |
redhat/jbcs-httpd24-apr | <1.6.3-104.jbcs.el7 | 1.6.3-104.jbcs.el7 |
redhat/jbcs-httpd24-apr-debuginfo | <1.6.3-104.jbcs.el7 | 1.6.3-104.jbcs.el7 |
redhat/jbcs-httpd24-apr-devel | <1.6.3-104.jbcs.el7 | 1.6.3-104.jbcs.el7 |
redhat/jbcs-httpd24-apr-util | <1.6.1-75.jbcs.el7 | 1.6.1-75.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-debuginfo | <1.6.1-75.jbcs.el7 | 1.6.1-75.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-devel | <1.6.1-75.jbcs.el7 | 1.6.1-75.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-ldap | <1.6.1-75.jbcs.el7 | 1.6.1-75.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-mysql | <1.6.1-75.jbcs.el7 | 1.6.1-75.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-nss | <1.6.1-75.jbcs.el7 | 1.6.1-75.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-odbc | <1.6.1-75.jbcs.el7 | 1.6.1-75.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-openssl | <1.6.1-75.jbcs.el7 | 1.6.1-75.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-pgsql | <1.6.1-75.jbcs.el7 | 1.6.1-75.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-sqlite | <1.6.1-75.jbcs.el7 | 1.6.1-75.jbcs.el7 |
redhat/jbcs-httpd24-brotli | <1.0.6-38.jbcs.el7 | 1.0.6-38.jbcs.el7 |
redhat/jbcs-httpd24-brotli-debuginfo | <1.0.6-38.jbcs.el7 | 1.0.6-38.jbcs.el7 |
redhat/jbcs-httpd24-brotli-devel | <1.0.6-38.jbcs.el7 | 1.0.6-38.jbcs.el7 |
redhat/jbcs-httpd24-curl | <7.64.1-44.jbcs.el7 | 7.64.1-44.jbcs.el7 |
redhat/jbcs-httpd24-curl-debuginfo | <7.64.1-44.jbcs.el7 | 7.64.1-44.jbcs.el7 |
redhat/jbcs-httpd24-httpd | <2.4.37-64.jbcs.el7 | 2.4.37-64.jbcs.el7 |
redhat/jbcs-httpd24-httpd-debuginfo | <2.4.37-64.jbcs.el7 | 2.4.37-64.jbcs.el7 |
redhat/jbcs-httpd24-httpd-devel | <2.4.37-64.jbcs.el7 | 2.4.37-64.jbcs.el7 |
redhat/jbcs-httpd24-httpd-manual | <2.4.37-64.jbcs.el7 | 2.4.37-64.jbcs.el7 |
redhat/jbcs-httpd24-httpd-selinux | <2.4.37-64.jbcs.el7 | 2.4.37-64.jbcs.el7 |
redhat/jbcs-httpd24-httpd-tools | <2.4.37-64.jbcs.el7 | 2.4.37-64.jbcs.el7 |
redhat/jbcs-httpd24-jansson | <2.11-53.jbcs.el7 | 2.11-53.jbcs.el7 |
redhat/jbcs-httpd24-jansson-debuginfo | <2.11-53.jbcs.el7 | 2.11-53.jbcs.el7 |
redhat/jbcs-httpd24-jansson-devel | <2.11-53.jbcs.el7 | 2.11-53.jbcs.el7 |
redhat/jbcs-httpd24-libcurl | <7.64.1-44.jbcs.el7 | 7.64.1-44.jbcs.el7 |
redhat/jbcs-httpd24-libcurl-devel | <7.64.1-44.jbcs.el7 | 7.64.1-44.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2 | <1.39.2-34.jbcs.el7 | 1.39.2-34.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2-debuginfo | <1.39.2-34.jbcs.el7 | 1.39.2-34.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2-devel | <1.39.2-34.jbcs.el7 | 1.39.2-34.jbcs.el7 |
redhat/jbcs-httpd24-openssl | <1.1.1c-32.jbcs.el7 | 1.1.1c-32.jbcs.el7 |
redhat/jbcs-httpd24-openssl-chil | <1.0.0-1.jbcs.el7 | 1.0.0-1.jbcs.el7 |
redhat/jbcs-httpd24-openssl-chil-debuginfo | <1.0.0-1.jbcs.el7 | 1.0.0-1.jbcs.el7 |
redhat/jbcs-httpd24-openssl-debuginfo | <1.1.1c-32.jbcs.el7 | 1.1.1c-32.jbcs.el7 |
redhat/jbcs-httpd24-openssl-devel | <1.1.1c-32.jbcs.el7 | 1.1.1c-32.jbcs.el7 |
redhat/jbcs-httpd24-openssl-libs | <1.1.1c-32.jbcs.el7 | 1.1.1c-32.jbcs.el7 |
redhat/jbcs-httpd24-openssl-perl | <1.1.1c-32.jbcs.el7 | 1.1.1c-32.jbcs.el7 |
redhat/jbcs-httpd24-openssl-static | <1.1.1c-32.jbcs.el7 | 1.1.1c-32.jbcs.el7 |
redhat/jbcs-httpd24-apr | <1.6.3-104.jbcs.el6 | 1.6.3-104.jbcs.el6 |
redhat/jbcs-httpd24-apr-util | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-brotli | <1.0.6-38.jbcs.el6 | 1.0.6-38.jbcs.el6 |
redhat/jbcs-httpd24-curl | <7.64.1-44.jbcs.el6 | 7.64.1-44.jbcs.el6 |
redhat/jbcs-httpd24-httpd | <2.4.37-64.jbcs.el6 | 2.4.37-64.jbcs.el6 |
redhat/jbcs-httpd24-jansson | <2.11-53.jbcs.el6 | 2.11-53.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2 | <1.39.2-34.jbcs.el6 | 1.39.2-34.jbcs.el6 |
redhat/jbcs-httpd24-openssl | <1.1.1c-32.jbcs.el6 | 1.1.1c-32.jbcs.el6 |
redhat/jbcs-httpd24-apr | <1.6.3-104.jbcs.el6 | 1.6.3-104.jbcs.el6 |
redhat/jbcs-httpd24-apr-debuginfo | <1.6.3-104.jbcs.el6 | 1.6.3-104.jbcs.el6 |
redhat/jbcs-httpd24-apr-devel | <1.6.3-104.jbcs.el6 | 1.6.3-104.jbcs.el6 |
redhat/jbcs-httpd24-apr-util | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-debuginfo | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-devel | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-ldap | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-mysql | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-nss | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-odbc | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-openssl | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-pgsql | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-sqlite | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-brotli | <1.0.6-38.jbcs.el6 | 1.0.6-38.jbcs.el6 |
redhat/jbcs-httpd24-brotli-debuginfo | <1.0.6-38.jbcs.el6 | 1.0.6-38.jbcs.el6 |
redhat/jbcs-httpd24-brotli-devel | <1.0.6-38.jbcs.el6 | 1.0.6-38.jbcs.el6 |
redhat/jbcs-httpd24-curl | <7.64.1-44.jbcs.el6 | 7.64.1-44.jbcs.el6 |
redhat/jbcs-httpd24-curl-debuginfo | <7.64.1-44.jbcs.el6 | 7.64.1-44.jbcs.el6 |
redhat/jbcs-httpd24-httpd | <2.4.37-64.jbcs.el6 | 2.4.37-64.jbcs.el6 |
redhat/jbcs-httpd24-httpd-debuginfo | <2.4.37-64.jbcs.el6 | 2.4.37-64.jbcs.el6 |
redhat/jbcs-httpd24-httpd-devel | <2.4.37-64.jbcs.el6 | 2.4.37-64.jbcs.el6 |
redhat/jbcs-httpd24-httpd-manual | <2.4.37-64.jbcs.el6 | 2.4.37-64.jbcs.el6 |
redhat/jbcs-httpd24-httpd-selinux | <2.4.37-64.jbcs.el6 | 2.4.37-64.jbcs.el6 |
redhat/jbcs-httpd24-httpd-tools | <2.4.37-64.jbcs.el6 | 2.4.37-64.jbcs.el6 |
redhat/jbcs-httpd24-jansson | <2.11-53.jbcs.el6 | 2.11-53.jbcs.el6 |
redhat/jbcs-httpd24-jansson-debuginfo | <2.11-53.jbcs.el6 | 2.11-53.jbcs.el6 |
redhat/jbcs-httpd24-jansson-devel | <2.11-53.jbcs.el6 | 2.11-53.jbcs.el6 |
redhat/jbcs-httpd24-libcurl | <7.64.1-44.jbcs.el6 | 7.64.1-44.jbcs.el6 |
redhat/jbcs-httpd24-libcurl-devel | <7.64.1-44.jbcs.el6 | 7.64.1-44.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2 | <1.39.2-34.jbcs.el6 | 1.39.2-34.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2-debuginfo | <1.39.2-34.jbcs.el6 | 1.39.2-34.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2-devel | <1.39.2-34.jbcs.el6 | 1.39.2-34.jbcs.el6 |
redhat/jbcs-httpd24-openssl | <1.1.1c-32.jbcs.el6 | 1.1.1c-32.jbcs.el6 |
redhat/jbcs-httpd24-openssl-debuginfo | <1.1.1c-32.jbcs.el6 | 1.1.1c-32.jbcs.el6 |
redhat/jbcs-httpd24-openssl-devel | <1.1.1c-32.jbcs.el6 | 1.1.1c-32.jbcs.el6 |
redhat/jbcs-httpd24-openssl-libs | <1.1.1c-32.jbcs.el6 | 1.1.1c-32.jbcs.el6 |
redhat/jbcs-httpd24-openssl-perl | <1.1.1c-32.jbcs.el6 | 1.1.1c-32.jbcs.el6 |
redhat/jbcs-httpd24-openssl-static | <1.1.1c-32.jbcs.el6 | 1.1.1c-32.jbcs.el6 |
redhat/jbcs-httpd24-apr-debuginfo | <1.6.3-104.jbcs.el6 | 1.6.3-104.jbcs.el6 |
redhat/jbcs-httpd24-apr-devel | <1.6.3-104.jbcs.el6 | 1.6.3-104.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-debuginfo | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-devel | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-ldap | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-mysql | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-nss | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-odbc | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-openssl | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-pgsql | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-apr-util-sqlite | <1.6.1-75.jbcs.el6 | 1.6.1-75.jbcs.el6 |
redhat/jbcs-httpd24-brotli-debuginfo | <1.0.6-38.jbcs.el6 | 1.0.6-38.jbcs.el6 |
redhat/jbcs-httpd24-brotli-devel | <1.0.6-38.jbcs.el6 | 1.0.6-38.jbcs.el6 |
redhat/jbcs-httpd24-curl-debuginfo | <7.64.1-44.jbcs.el6 | 7.64.1-44.jbcs.el6 |
redhat/jbcs-httpd24-httpd-debuginfo | <2.4.37-64.jbcs.el6 | 2.4.37-64.jbcs.el6 |
redhat/jbcs-httpd24-httpd-devel | <2.4.37-64.jbcs.el6 | 2.4.37-64.jbcs.el6 |
redhat/jbcs-httpd24-httpd-selinux | <2.4.37-64.jbcs.el6 | 2.4.37-64.jbcs.el6 |
redhat/jbcs-httpd24-httpd-tools | <2.4.37-64.jbcs.el6 | 2.4.37-64.jbcs.el6 |
redhat/jbcs-httpd24-jansson-debuginfo | <2.11-53.jbcs.el6 | 2.11-53.jbcs.el6 |
redhat/jbcs-httpd24-jansson-devel | <2.11-53.jbcs.el6 | 2.11-53.jbcs.el6 |
redhat/jbcs-httpd24-libcurl | <7.64.1-44.jbcs.el6 | 7.64.1-44.jbcs.el6 |
redhat/jbcs-httpd24-libcurl-devel | <7.64.1-44.jbcs.el6 | 7.64.1-44.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2-debuginfo | <1.39.2-34.jbcs.el6 | 1.39.2-34.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2-devel | <1.39.2-34.jbcs.el6 | 1.39.2-34.jbcs.el6 |
redhat/jbcs-httpd24-openssl-debuginfo | <1.1.1c-32.jbcs.el6 | 1.1.1c-32.jbcs.el6 |
redhat/jbcs-httpd24-openssl-devel | <1.1.1c-32.jbcs.el6 | 1.1.1c-32.jbcs.el6 |
redhat/jbcs-httpd24-openssl-libs | <1.1.1c-32.jbcs.el6 | 1.1.1c-32.jbcs.el6 |
redhat/jbcs-httpd24-openssl-perl | <1.1.1c-32.jbcs.el6 | 1.1.1c-32.jbcs.el6 |
redhat/jbcs-httpd24-openssl-static | <1.1.1c-32.jbcs.el6 | 1.1.1c-32.jbcs.el6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.