First published: Thu Jun 17 2021(Updated: )
This release adds the new Apache HTTP Server 2.4.37 Service Pack 8 packages that are part of the JBoss Core Services offering.<br>This release serves as a replacement for Red Hat JBoss Core Services Pack Apache Server 2.4.37 Service Pack 7 and includes bug fixes and enhancements. Refer to the Release Notes for information on the most significant bug fixes and enhancements included in this release.<br>Security Fix(es):<br><li> curl: Use-after-free in TLS session handling when using OpenSSL TLS backend (CVE-2021-22901)</li> <li> httpd: NULL pointer dereference on specially crafted HTTP/2 request (CVE-2021-31618)</li> <li> libcurl: partial password leak over DNS on HTTP redirect (CVE-2020-8169)</li> <li> curl: FTP PASV command response can cause curl to connect to arbitrary host (CVE-2020-8284)</li> <li> curl: Malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used (CVE-2020-8285)</li> <li> curl: Inferior OCSP verification (CVE-2020-8286)</li> <li> curl: Leak of authentication credentials in URL via automatic Referer (CVE-2021-22876)</li> <li> curl: TLS 1.3 session ticket mix-up with HTTPS proxy host (CVE-2021-22890)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jbcs-httpd24 | <1-18.el8 | 1-18.el8 |
redhat/jbcs-httpd24-apr | <1.6.3-105.el8 | 1.6.3-105.el8 |
redhat/jbcs-httpd24-apr-util | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-brotli | <1.0.6-40.el8 | 1.0.6-40.el8 |
redhat/jbcs-httpd24-curl | <7.77.0-2.el8 | 7.77.0-2.el8 |
redhat/jbcs-httpd24-httpd | <2.4.37-74.el8 | 2.4.37-74.el8 |
redhat/jbcs-httpd24-jansson | <2.11-55.el8 | 2.11-55.el8 |
redhat/jbcs-httpd24-nghttp2 | <1.39.2-37.el8 | 1.39.2-37.el8 |
redhat/jbcs-httpd24-openssl | <1.1.1g-6.el8 | 1.1.1g-6.el8 |
redhat/jbcs-httpd24-openssl-chil | <1.0.0-5.el8 | 1.0.0-5.el8 |
redhat/jbcs-httpd24-openssl-pkcs11 | <0.4.10-20.el8 | 0.4.10-20.el8 |
redhat/jbcs-httpd24-apr-debuginfo | <1.6.3-105.el8 | 1.6.3-105.el8 |
redhat/jbcs-httpd24-apr-devel | <1.6.3-105.el8 | 1.6.3-105.el8 |
redhat/jbcs-httpd24-apr-util-debuginfo | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-devel | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-ldap | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-ldap-debuginfo | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-mysql | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-mysql-debuginfo | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-nss | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-nss-debuginfo | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-odbc | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-odbc-debuginfo | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-openssl | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-openssl-debuginfo | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-pgsql | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-pgsql-debuginfo | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-sqlite | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-apr-util-sqlite-debuginfo | <1.6.1-82.el8 | 1.6.1-82.el8 |
redhat/jbcs-httpd24-brotli-debuginfo | <1.0.6-40.el8 | 1.0.6-40.el8 |
redhat/jbcs-httpd24-brotli-devel | <1.0.6-40.el8 | 1.0.6-40.el8 |
redhat/jbcs-httpd24-curl-debuginfo | <7.77.0-2.el8 | 7.77.0-2.el8 |
redhat/jbcs-httpd24-httpd-debuginfo | <2.4.37-74.el8 | 2.4.37-74.el8 |
redhat/jbcs-httpd24-httpd-devel | <2.4.37-74.el8 | 2.4.37-74.el8 |
redhat/jbcs-httpd24-httpd-manual | <2.4.37-74.el8 | 2.4.37-74.el8 |
redhat/jbcs-httpd24-httpd-selinux | <2.4.37-74.el8 | 2.4.37-74.el8 |
redhat/jbcs-httpd24-httpd-tools | <2.4.37-74.el8 | 2.4.37-74.el8 |
redhat/jbcs-httpd24-httpd-tools-debuginfo | <2.4.37-74.el8 | 2.4.37-74.el8 |
redhat/jbcs-httpd24-jansson-debuginfo | <2.11-55.el8 | 2.11-55.el8 |
redhat/jbcs-httpd24-jansson-devel | <2.11-55.el8 | 2.11-55.el8 |
redhat/jbcs-httpd24-libcurl | <7.77.0-2.el8 | 7.77.0-2.el8 |
redhat/jbcs-httpd24-libcurl-debuginfo | <7.77.0-2.el8 | 7.77.0-2.el8 |
redhat/jbcs-httpd24-libcurl-devel | <7.77.0-2.el8 | 7.77.0-2.el8 |
redhat/jbcs-httpd24-nghttp2-debuginfo | <1.39.2-37.el8 | 1.39.2-37.el8 |
redhat/jbcs-httpd24-nghttp2-devel | <1.39.2-37.el8 | 1.39.2-37.el8 |
redhat/jbcs-httpd24-openssl-chil-debuginfo | <1.0.0-5.el8 | 1.0.0-5.el8 |
redhat/jbcs-httpd24-openssl-debuginfo | <1.1.1g-6.el8 | 1.1.1g-6.el8 |
redhat/jbcs-httpd24-openssl-devel | <1.1.1g-6.el8 | 1.1.1g-6.el8 |
redhat/jbcs-httpd24-openssl-libs | <1.1.1g-6.el8 | 1.1.1g-6.el8 |
redhat/jbcs-httpd24-openssl-libs-debuginfo | <1.1.1g-6.el8 | 1.1.1g-6.el8 |
redhat/jbcs-httpd24-openssl-perl | <1.1.1g-6.el8 | 1.1.1g-6.el8 |
redhat/jbcs-httpd24-openssl-pkcs11-debuginfo | <0.4.10-20.el8 | 0.4.10-20.el8 |
redhat/jbcs-httpd24-openssl-static | <1.1.1g-6.el8 | 1.1.1g-6.el8 |
redhat/jbcs-httpd24-runtime | <1-18.el8 | 1-18.el8 |
redhat/jbcs-httpd24 | <1-18.jbcs.el7 | 1-18.jbcs.el7 |
redhat/jbcs-httpd24-apr | <1.6.3-105.jbcs.el7 | 1.6.3-105.jbcs.el7 |
redhat/jbcs-httpd24-apr-util | <1.6.1-82.jbcs.el7 | 1.6.1-82.jbcs.el7 |
redhat/jbcs-httpd24-curl | <7.77.0-2.jbcs.el7 | 7.77.0-2.jbcs.el7 |
redhat/jbcs-httpd24-httpd | <2.4.37-74.jbcs.el7 | 2.4.37-74.jbcs.el7 |
redhat/jbcs-httpd24-jansson | <2.11-55.jbcs.el7 | 2.11-55.jbcs.el7 |
redhat/jbcs-httpd24 | <1-18.jbcs.el7 | 1-18.jbcs.el7 |
redhat/jbcs-httpd24-apr | <1.6.3-105.jbcs.el7 | 1.6.3-105.jbcs.el7 |
redhat/jbcs-httpd24-apr-debuginfo | <1.6.3-105.jbcs.el7 | 1.6.3-105.jbcs.el7 |
redhat/jbcs-httpd24-apr-devel | <1.6.3-105.jbcs.el7 | 1.6.3-105.jbcs.el7 |
redhat/jbcs-httpd24-apr-util | <1.6.1-82.jbcs.el7 | 1.6.1-82.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-debuginfo | <1.6.1-82.jbcs.el7 | 1.6.1-82.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-devel | <1.6.1-82.jbcs.el7 | 1.6.1-82.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-ldap | <1.6.1-82.jbcs.el7 | 1.6.1-82.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-mysql | <1.6.1-82.jbcs.el7 | 1.6.1-82.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-nss | <1.6.1-82.jbcs.el7 | 1.6.1-82.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-odbc | <1.6.1-82.jbcs.el7 | 1.6.1-82.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-openssl | <1.6.1-82.jbcs.el7 | 1.6.1-82.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-pgsql | <1.6.1-82.jbcs.el7 | 1.6.1-82.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-sqlite | <1.6.1-82.jbcs.el7 | 1.6.1-82.jbcs.el7 |
redhat/jbcs-httpd24-curl | <7.77.0-2.jbcs.el7 | 7.77.0-2.jbcs.el7 |
redhat/jbcs-httpd24-curl-debuginfo | <7.77.0-2.jbcs.el7 | 7.77.0-2.jbcs.el7 |
redhat/jbcs-httpd24-httpd | <2.4.37-74.jbcs.el7 | 2.4.37-74.jbcs.el7 |
redhat/jbcs-httpd24-httpd-debuginfo | <2.4.37-74.jbcs.el7 | 2.4.37-74.jbcs.el7 |
redhat/jbcs-httpd24-httpd-devel | <2.4.37-74.jbcs.el7 | 2.4.37-74.jbcs.el7 |
redhat/jbcs-httpd24-httpd-manual | <2.4.37-74.jbcs.el7 | 2.4.37-74.jbcs.el7 |
redhat/jbcs-httpd24-httpd-selinux | <2.4.37-74.jbcs.el7 | 2.4.37-74.jbcs.el7 |
redhat/jbcs-httpd24-httpd-tools | <2.4.37-74.jbcs.el7 | 2.4.37-74.jbcs.el7 |
redhat/jbcs-httpd24-jansson | <2.11-55.jbcs.el7 | 2.11-55.jbcs.el7 |
redhat/jbcs-httpd24-jansson-debuginfo | <2.11-55.jbcs.el7 | 2.11-55.jbcs.el7 |
redhat/jbcs-httpd24-jansson-devel | <2.11-55.jbcs.el7 | 2.11-55.jbcs.el7 |
redhat/jbcs-httpd24-libcurl | <7.77.0-2.jbcs.el7 | 7.77.0-2.jbcs.el7 |
redhat/jbcs-httpd24-libcurl-devel | <7.77.0-2.jbcs.el7 | 7.77.0-2.jbcs.el7 |
redhat/jbcs-httpd24-runtime | <1-18.jbcs.el7 | 1-18.jbcs.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.