First published: Wed Nov 10 2021(Updated: )
This release adds the new Apache HTTP Server 2.4.37 Service Pack 10 packages that are part of the JBoss Core Services offering.<br>This release serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 9 and includes bug fixes and enhancements. Refer to the Release Notes for information on the most significant bug fixes and enhancements included in this release.<br>Security Fix(es):<br><li> httpd: Single zero byte stack overflow in mod_auth_digest (CVE-2020-35452)</li> <li> httpd: mod_session NULL pointer dereference in parser (CVE-2021-26690)</li> <li> httpd: Heap overflow in mod_session (CVE-2021-26691)</li> <li> httpd: mod_proxy_wstunnel tunneling of non Upgraded connection (CVE-2019-17567)</li> <li> httpd: MergeSlashes regression (CVE-2021-30641)</li> <li> httpd: mod_proxy NULL pointer dereference (CVE-2020-13950)</li> <li> jbcs-httpd24-openssl: openssl: NULL pointer dereference in X509_issuer_and_serial_hash() (CVE-2021-23841)</li> <li> openssl: Read buffer overruns processing ASN.1 strings (CVE-2021-3712)</li> <li> openssl: integer overflow in CipherUpdate (CVE-2021-23840)</li> <li> pcre: buffer over-read in JIT when UTF is disabled (CVE-2019-20838)</li> <li> pcre: integer overflow in libpcre (CVE-2020-14155)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jbcs-httpd24-apr | <1.6.3-107.el8 | 1.6.3-107.el8 |
redhat/jbcs-httpd24-apr-util | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-curl | <7.78.0-2.el8 | 7.78.0-2.el8 |
redhat/jbcs-httpd24-httpd | <2.4.37-78.el8 | 2.4.37-78.el8 |
redhat/jbcs-httpd24-nghttp2 | <1.39.2-39.el8 | 1.39.2-39.el8 |
redhat/jbcs-httpd24-openssl | <1.1.1g-8.el8 | 1.1.1g-8.el8 |
redhat/jbcs-httpd24-openssl-chil | <1.0.0-7.el8 | 1.0.0-7.el8 |
redhat/jbcs-httpd24-openssl-pkcs11 | <0.4.10-22.el8 | 0.4.10-22.el8 |
redhat/jbcs-httpd24-apr-debuginfo | <1.6.3-107.el8 | 1.6.3-107.el8 |
redhat/jbcs-httpd24-apr-devel | <1.6.3-107.el8 | 1.6.3-107.el8 |
redhat/jbcs-httpd24-apr-util-debuginfo | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-devel | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-ldap | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-ldap-debuginfo | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-mysql | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-mysql-debuginfo | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-nss | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-nss-debuginfo | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-odbc | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-odbc-debuginfo | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-openssl | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-openssl-debuginfo | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-pgsql | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-pgsql-debuginfo | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-sqlite | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-apr-util-sqlite-debuginfo | <1.6.1-84.el8 | 1.6.1-84.el8 |
redhat/jbcs-httpd24-curl-debuginfo | <7.78.0-2.el8 | 7.78.0-2.el8 |
redhat/jbcs-httpd24-httpd-debuginfo | <2.4.37-78.el8 | 2.4.37-78.el8 |
redhat/jbcs-httpd24-httpd-devel | <2.4.37-78.el8 | 2.4.37-78.el8 |
redhat/jbcs-httpd24-httpd-manual | <2.4.37-78.el8 | 2.4.37-78.el8 |
redhat/jbcs-httpd24-httpd-selinux | <2.4.37-78.el8 | 2.4.37-78.el8 |
redhat/jbcs-httpd24-httpd-tools | <2.4.37-78.el8 | 2.4.37-78.el8 |
redhat/jbcs-httpd24-httpd-tools-debuginfo | <2.4.37-78.el8 | 2.4.37-78.el8 |
redhat/jbcs-httpd24-libcurl | <7.78.0-2.el8 | 7.78.0-2.el8 |
redhat/jbcs-httpd24-libcurl-debuginfo | <7.78.0-2.el8 | 7.78.0-2.el8 |
redhat/jbcs-httpd24-libcurl-devel | <7.78.0-2.el8 | 7.78.0-2.el8 |
redhat/jbcs-httpd24-nghttp2-debuginfo | <1.39.2-39.el8 | 1.39.2-39.el8 |
redhat/jbcs-httpd24-nghttp2-devel | <1.39.2-39.el8 | 1.39.2-39.el8 |
redhat/jbcs-httpd24-openssl-chil-debuginfo | <1.0.0-7.el8 | 1.0.0-7.el8 |
redhat/jbcs-httpd24-openssl-debuginfo | <1.1.1g-8.el8 | 1.1.1g-8.el8 |
redhat/jbcs-httpd24-openssl-devel | <1.1.1g-8.el8 | 1.1.1g-8.el8 |
redhat/jbcs-httpd24-openssl-libs | <1.1.1g-8.el8 | 1.1.1g-8.el8 |
redhat/jbcs-httpd24-openssl-libs-debuginfo | <1.1.1g-8.el8 | 1.1.1g-8.el8 |
redhat/jbcs-httpd24-openssl-perl | <1.1.1g-8.el8 | 1.1.1g-8.el8 |
redhat/jbcs-httpd24-openssl-pkcs11-debuginfo | <0.4.10-22.el8 | 0.4.10-22.el8 |
redhat/jbcs-httpd24-openssl-static | <1.1.1g-8.el8 | 1.1.1g-8.el8 |
redhat/jbcs-httpd24-apr | <1.6.3-107.jbcs.el7 | 1.6.3-107.jbcs.el7 |
redhat/jbcs-httpd24-apr-util | <1.6.1-84.jbcs.el7 | 1.6.1-84.jbcs.el7 |
redhat/jbcs-httpd24-curl | <7.78.0-2.jbcs.el7 | 7.78.0-2.jbcs.el7 |
redhat/jbcs-httpd24-httpd | <2.4.37-78.jbcs.el7 | 2.4.37-78.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2 | <1.39.2-39.jbcs.el7 | 1.39.2-39.jbcs.el7 |
redhat/jbcs-httpd24-openssl | <1.1.1g-8.jbcs.el7 | 1.1.1g-8.jbcs.el7 |
redhat/jbcs-httpd24-openssl-chil | <1.0.0-7.jbcs.el7 | 1.0.0-7.jbcs.el7 |
redhat/jbcs-httpd24-openssl-pkcs11 | <0.4.10-22.jbcs.el7 | 0.4.10-22.jbcs.el7 |
redhat/jbcs-httpd24-apr | <1.6.3-107.jbcs.el7 | 1.6.3-107.jbcs.el7 |
redhat/jbcs-httpd24-apr-debuginfo | <1.6.3-107.jbcs.el7 | 1.6.3-107.jbcs.el7 |
redhat/jbcs-httpd24-apr-devel | <1.6.3-107.jbcs.el7 | 1.6.3-107.jbcs.el7 |
redhat/jbcs-httpd24-apr-util | <1.6.1-84.jbcs.el7 | 1.6.1-84.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-debuginfo | <1.6.1-84.jbcs.el7 | 1.6.1-84.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-devel | <1.6.1-84.jbcs.el7 | 1.6.1-84.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-ldap | <1.6.1-84.jbcs.el7 | 1.6.1-84.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-mysql | <1.6.1-84.jbcs.el7 | 1.6.1-84.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-nss | <1.6.1-84.jbcs.el7 | 1.6.1-84.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-odbc | <1.6.1-84.jbcs.el7 | 1.6.1-84.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-openssl | <1.6.1-84.jbcs.el7 | 1.6.1-84.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-pgsql | <1.6.1-84.jbcs.el7 | 1.6.1-84.jbcs.el7 |
redhat/jbcs-httpd24-apr-util-sqlite | <1.6.1-84.jbcs.el7 | 1.6.1-84.jbcs.el7 |
redhat/jbcs-httpd24-curl | <7.78.0-2.jbcs.el7 | 7.78.0-2.jbcs.el7 |
redhat/jbcs-httpd24-curl-debuginfo | <7.78.0-2.jbcs.el7 | 7.78.0-2.jbcs.el7 |
redhat/jbcs-httpd24-httpd | <2.4.37-78.jbcs.el7 | 2.4.37-78.jbcs.el7 |
redhat/jbcs-httpd24-httpd-debuginfo | <2.4.37-78.jbcs.el7 | 2.4.37-78.jbcs.el7 |
redhat/jbcs-httpd24-httpd-devel | <2.4.37-78.jbcs.el7 | 2.4.37-78.jbcs.el7 |
redhat/jbcs-httpd24-httpd-manual | <2.4.37-78.jbcs.el7 | 2.4.37-78.jbcs.el7 |
redhat/jbcs-httpd24-httpd-selinux | <2.4.37-78.jbcs.el7 | 2.4.37-78.jbcs.el7 |
redhat/jbcs-httpd24-httpd-tools | <2.4.37-78.jbcs.el7 | 2.4.37-78.jbcs.el7 |
redhat/jbcs-httpd24-libcurl | <7.78.0-2.jbcs.el7 | 7.78.0-2.jbcs.el7 |
redhat/jbcs-httpd24-libcurl-devel | <7.78.0-2.jbcs.el7 | 7.78.0-2.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2 | <1.39.2-39.jbcs.el7 | 1.39.2-39.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2-debuginfo | <1.39.2-39.jbcs.el7 | 1.39.2-39.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2-devel | <1.39.2-39.jbcs.el7 | 1.39.2-39.jbcs.el7 |
redhat/jbcs-httpd24-openssl | <1.1.1g-8.jbcs.el7 | 1.1.1g-8.jbcs.el7 |
redhat/jbcs-httpd24-openssl-chil | <1.0.0-7.jbcs.el7 | 1.0.0-7.jbcs.el7 |
redhat/jbcs-httpd24-openssl-chil-debuginfo | <1.0.0-7.jbcs.el7 | 1.0.0-7.jbcs.el7 |
redhat/jbcs-httpd24-openssl-debuginfo | <1.1.1g-8.jbcs.el7 | 1.1.1g-8.jbcs.el7 |
redhat/jbcs-httpd24-openssl-devel | <1.1.1g-8.jbcs.el7 | 1.1.1g-8.jbcs.el7 |
redhat/jbcs-httpd24-openssl-libs | <1.1.1g-8.jbcs.el7 | 1.1.1g-8.jbcs.el7 |
redhat/jbcs-httpd24-openssl-perl | <1.1.1g-8.jbcs.el7 | 1.1.1g-8.jbcs.el7 |
redhat/jbcs-httpd24-openssl-pkcs11 | <0.4.10-22.jbcs.el7 | 0.4.10-22.jbcs.el7 |
redhat/jbcs-httpd24-openssl-pkcs11-debuginfo | <0.4.10-22.jbcs.el7 | 0.4.10-22.jbcs.el7 |
redhat/jbcs-httpd24-openssl-static | <1.1.1g-8.jbcs.el7 | 1.1.1g-8.jbcs.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.