Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products, and is packaged under Red Hat JBoss Core Services to allow for faster distribution of updates, and for a more consistent update experience.<br>This release adds the new Apache HTTP Server 2.4.29 Service Pack 2 packages that are part of the JBoss Core Services offering. It serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.29 SP1, and includes bug fixes and enhancements. Refer to the Release Notes for information on the most significant bug fixes, enhancements and component upgrades included in this release.<br>Security Fix(es):<br><li> openssl: Malicious server can send large prime to client during DH(E) TLS handshake causing the client to hang (CVE-2018-0732)</li> <li> openssl: ROHNP - Key Extraction Side Channel in Multiple Crypto Libraries (CVE-2018-0495)</li> <li> httpd: privilege escalation from modules scripts (CVE-2019-0211)</li> Details around this issue, including information about the CVE, severity of the issue, and CVSS scores can be found on the CVE pages listed in the References section below.
This release adds the new Apache HTTP Server 2.4.29 packages that are part<br>of the JBoss Core Services offering.<br>This release serves as a replacement for Red Hat JBoss Core Services<br>Apache HTTP Server 2.4.23, and includes bug fixes and enhancements. Refer<br>to the Release Notes for information on the most significant bug fixes,<br>enhancements and component upgrades included in this release.<br>Security Fix(es):<br><li> expat: Out-of-bounds heap read on crafted input causing crash (CVE-2016-0718)</li> <li> curl: escape and unescape integer overflows (CVE-2016-7167)</li> <li> curl: Cookie injection for other servers (CVE-2016-8615)</li> <li> curl: Case insensitive password comparison (CVE-2016-8616)</li> <li> curl: Out-of-bounds write via unchecked multiplication (CVE-2016-8617)</li> <li> curl: Double-free in curlmaprintf (CVE-2016-8618)</li> <li> curl: Double-free in krb5 code (CVE-2016-8619)</li> <li> curl: curlgetdate out-of-bounds read (CVE-2016-8621)</li> <li> curl: URL unescape heap overflow via integer truncation (CVE-2016-8622)</li> <li> curl: Use-after-free via shared cookies (CVE-2016-8623)</li> <li> curl: Invalid URL parsing with '#' (CVE-2016-8624)</li> <li> curl: IDNA 2003 makes curl use wrong host (CVE-2016-8625)</li> <li> libxml2: out-of-bounds read (unfixed CVE-2016-4483 in JBCS) (CVE-2016-9598)</li> <li> pcre: Out-of-bounds read in compilebracketmatchingpath function (8.41/3) (CVE-2017-6004)</li> <li> pcre: Invalid Unicode property lookup (8.41/7, 10.24/2) (CVE-2017-7186)</li> <li> pcre: invalid memory read inpcre32xclass (pcrexclass.c) (CVE-2017-7244)</li> <li> pcre: stack-based buffer overflow write in pcre32copysubstring (CVE-2017-7245)</li> <li> pcre: stack-based buffer overflow write in pcre32copysubstring (CVE-2017-7246)</li> <li> curl: FTP PWD response parser out of bounds read (CVE-2017-1000254)</li> <li> curl: IMAP FETCH response out of bounds read (CVE-2017-1000257)</li> <li> curl: Heap-based buffer overflow in Curlsmtpescapeeob() when uploading data over SMTP (CVE-2018-0500)</li> Details around this issue, including information about the CVE, severity of<br>the issue, and the CVSS score can be found on the CVE page listed in the<br>Reference section below.<br>The following packages have been upgraded to a newer upstream version:<br><li> Curl (7.57.0)</li> <li> OpenSSL (1.0.2n)</li> <li> Expat (2.2.5)</li> <li> PCRE (8.41)</li> <li> libxml2 (2.9.7)</li> Acknowledgements:<br>CVE-2017-1000254: Red Hat would like to thank Daniel Stenberg for reporting this issue.<br>Upstream acknowledges Max Dymond as the original reporter.<br>CVE-2017-1000257: Red Hat would like to thank the Curl project for reporting this issue. Upstream acknowledges Brian Carpenter, (the OSS-Fuzz project) as the original reporter.<br>CVE-2018-0500: Red Hat would like to thank the Curl project for reporting this issue.
This release adds the new Apache HTTP Server 2.4.29 Service Pack 1 packages that are part<br>of the JBoss Core Services offering.<br>This release serves as a replacement for Red Hat JBoss Core Services<br>Apache HTTP Server 2.4.29, and includes bug fixes and enhancements. Refer<br>to the Release Notes for information on the most significant bug fixes,<br>enhancements and component upgrades included in this release.<br>Security Fix(es):<br><li> db4: libdb: Reads DBCONFIG from the current working directory (CVE-2017-10140)</li> <li> httpd: DoS for HTTP/2 connections by continuous SETTINGS (CVE-2018-11763)</li> <li> httpd: Weak Digest auth nonce generation in modauthdigest (CVE-2018-1312)</li> <li> httpd: Out of bound access after failure in reading the HTTP request (CVE-2018-1301)</li> <li> httpd: Use-after-free on HTTP/2 stream shutdown (CVE-2018-1302)</li> <li> httpd: <FilesMatch> bypass with a trailing newline in the file name (CVE-2017-15715)</li> <li> httpd: Out of bound write in modauthnzldap when using too small Accept-Language values (CVE-2017-15710)</li> <li> httpd: Out of bounds read in modcachesocache can allow a remote attacker to cause a denial of service (CVE-2018-1303)</li> <li> httpd: Improper handling of headers in modsession can allow a remote user to modify session data for CGI applications (CVE-2018-1283)</li> <li> httpd: modhttp2: too much time allocated to workers, possibly leading to DoS (CVE-2018-1333)</li> <li> modjk: connector path traversal due to mishandled HTTP requests in httpd (CVE-2018-11759)</li> <li> nghttp2: Null pointer dereference when too large ALTSVC frame is received (CVE-2018-1000168)</li> <li> openssl: Handling of crafted recursive ASN.1 structures can cause a stack overflow and resulting denial of service (CVE-2018-0739)</li> Details around this issue, including information about the CVE, severity of<br>the issue, and the CVSS score can be found on the CVE page listed in the<br>Reference section below.<br>The CVE-2018-1000168 issue was discovered by The Nghttp2 Project.
Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products, and is packaged under Red Hat JBoss Core Services to allow for faster distribution of updates, and for a more consistent update experience.<br>This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.23 Service Pack 4 serves as a replacement of Red Hat JBoss Core Services Apache HTTP Server 2.4.23, and includes bug fixes (including fixes from previous Service Pack 1,2 and 3), which are documented in the Release Notes document linked to in the References. <br>Security Fix(es):<br>Details around this issue, including information about the CVE, severity of the issue, and the CVSS score can be found on the CVE page listed in the Reference section below.<br><li> chromium-browser: use after free in libxml (CVE-2017-15412, Important)</li>
Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products, and is packaged under Red Hat JBoss Core Services to allow for faster distribution of updates, and for a more consistent update experience.<br>This release adds the new Apache HTTP Server 2.4.37 packages that are part of the JBoss Core Services offering.<br>This release serves as a replacement for Red Hat JBoss Core Services Pack Apache Server 2.4.29 and includes bug fixes and enhancements. Refer to the Release Notes for information on the most significant bug fixes and enhancements included in this release.<br>Security Fix(es):<br><li> openssl: RSA key generation cache timing vulnerability in crypto/rsa/rsagen.c allows attackers to recover private keys (CVE-2018-0737) openssl: timing side channel attack in the DSA signature algorithm (CVE-2018-0734) modauthdigest: access control bypass due to race condition (CVE-2019-0217) openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) (CVE-2018-5407) modsessioncookie does not respect expiry time (CVE-2018-17199) modhttp2: DoS via slow, unneeded request bodies (CVE-2018-17189) modhttp2: possible crash on late upgrade (CVE-2019-0197) modhttp2: read-after-free on a string compare (CVE-2019-0196) nghttp2: HTTP/2: large amount of data request leads to denial of service (CVE-2019-9511) nghttp2: HTTP/2: flood using PRIORITY frames resulting in excessive resource consumption (CVE-2019-9513) modhttp2: HTTP/2: 0-length headers leads to denial of service (CVE-2019-9516) modhttp2: HTTP/2: request for large response leads to denial of service (CVE-2019-9517)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products, and is packaged under Red Hat JBoss Core Services to allow for faster distribution of updates, and for a more consistent update experience.<br>This release adds the new Apache HTTP Server 2.4.37 Service Pack 11 packages that are part of the JBoss Core Services offering.<br>This release serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 10 and includes bug fixes and enhancements. Refer to the Release Notes for information on the most significant bug fixes and enhancements included in this release.<br>Security Fix(es):<br><li> jbcs-httpd24-httpd: httpd: HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier (CVE-2022-22720)</li> <li> libxml2: use-after-free in xmlXIncludeDoProcess() in xinclude.c (CVE-2021-3518)</li> <li> libxml2: heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c (CVE-2021-3517)</li> <li> libxml2: use-after-free in xmlEncodeEntitiesInternal() in entities.c (CVE-2021-3516)</li> <li> libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms (CVE-2021-3541)</li> <li> libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode (CVE-2021-3537)</li> <li> libxml2: Use-after-free of ID and IDREF attributes (CVE-2022-23308)</li> <li> openssl: Infinite loop in BNmodsqrt() reachable when parsing certificates (CVE-2022-0778)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products, and is packaged under Red Hat JBoss Core Services to allow for faster distribution of updates, and for a more consistent update experience.<br>This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.51 serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 10, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> zlib: A flaw found in zlib when compressing (not decompressing) certain inputs (CVE-2018-25032)</li> <li> expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235)</li> <li> expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution (CVE-2022-25236)</li> <li> expat: Integer overflow in storeRawNames() (CVE-2022-25315)</li> <li> httpd: Request splitting via HTTP/2 method injection and modproxy (CVE-2021-33193)</li> <li> httpd: modproxyuwsgi: out-of-bounds read via a crafted request uri-path (CVE-2021-36160)</li> <li> httpd: Out-of-bounds write in apescapequotes() via malicious input (CVE-2021-39275)</li> <li> httpd: NULL pointer dereference via crafted request during HTTP/2 request processing (CVE-2021-41524)</li> <li> httpd: possible NULL dereference or SSRF in forward proxy configurations (CVE-2021-44224)</li> <li> expat: Large number of prefixed XML attributes on a single tag can crash libexpat (CVE-2021-45960)</li> <li> expat: Integer overflow in doProlog in xmlparse.c (CVE-2021-46143)</li> <li> expat: Integer overflow in addBinding in xmlparse.c (CVE-2022-22822)</li> <li> expat: Integer overflow in buildmodel in xmlparse.c (CVE-2022-22823)</li> <li> expat: Integer overflow in defineAttribute in xmlparse.c (CVE-2022-22824)</li> <li> expat: Integer overflow in lookup in xmlparse.c (CVE-2022-22825)</li> <li> expat: Integer overflow in nextScaffoldPart in xmlparse.c (CVE-2022-22826)</li> <li> expat: Integer overflow in storeAtts in xmlparse.c (CVE-2022-22827)</li> <li> expat: Integer overflow in function XMLGetBuffer (CVE-2022-23852)</li> <li> expat: stack exhaustion in doctype parsing (CVE-2022-25313)</li> <li> expat: integer overflow in copyString() (CVE-2022-25314)</li> <li> expat: integer overflow in the doProlog function (CVE-2022-23990)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products, and is packaged under Red Hat JBoss Core Services to allow for faster distribution of updates, and for a more consistent update experience.<br>This release adds the new Apache HTTP Server 2.4.37 Service Pack 2 packages that are part of the JBoss Core Services offering.<br>This release serves as a replacement for Red Hat JBoss Core Services Pack Apache Server 2.4.37 Service Pack 1 and includes bug fixes and enhancements. Refer to the Release Notes for information on the most significant bug fixes and enhancements included in this release.<br>Security Fix(es):<br><li> openssl: side-channel weak encryption vulnerability (CVE-2019-1547)</li> <li> httpd: memory corruption on early pushes (CVE-2019-10081)</li> <li> httpd: read-after-free in h2 connection shutdown (CVE-2019-10082)</li> <li> httpd: null-pointer dereference in modremoteip (CVE-2019-10097)</li> <li> openssl: information disclosure in fork() (CVE-2019-1549)</li> <li> openssl: information disclosure in PKCS7dataDecode and CMSdecryptset1pkey (CVE-2019-1563)</li> <li> httpd: limited cross-site scripting in modproxy error page (CVE-2019-10092)</li> <li> httpd: modrewrite potential open redirect (CVE-2019-10098)</li> <li> httpd: modrewrite configurations vulnerable to open redirect(CVE-2020-1927)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products, and is packaged under Red Hat JBoss Core Services to allow for faster distribution of updates, and for a more consistent update experience.<br>This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.23 Service Pack 5 serves as a replacement of Red Hat JBoss Core Services Web Server Connectors 2.4.23 and includes bug fixes, which are documented in the Release Notes document linked to in the References. <br>Security Fix(es):<br><li> isapiredirect: Mishandled HTTP request paths in jkisapiplugin.c can lead to unintended exposure of application resources via the reverse proxy (CVE-2018-1323)</li> Details around this issue, including information about the CVE, severity of the issue, and the CVSS score can be found on the CVE page listed in the Reference section below.
Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products, and is packaged under Red Hat JBoss Core Services to allow for faster distribution of updates, and for a more consistent update experience.<br>This release adds the new Apache HTTP Server 2.4.37 Service Pack 5 packages that are part of the JBoss Core Services offering.<br>This release serves as a replacement for Red Hat JBoss Core Services Pack Apache Server 2.4.37 Service Pack 4 and includes bug fixes and enhancements. Refer to the Release Notes for information on the most significant bug fixes and enhancements included in this release.<br>Security fix(es):<br><li> curl: Integer overflows in curlurlset() function (CVE-2019-5435)</li> <li> openssl: Integer overflow in RSAZ modular exponentiation on x8664 (CVE-2019-1551)</li> <li> httpd: modhttp2 concurrent pool usage (CVE-2020-11993)</li> <li> httpd: modproxyuswgi buffer overflow (CVE-2020-11984)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products, and is packaged under Red Hat JBoss Core Services to allow for faster distribution of updates, and for a more consistent update experience.<br>This release adds the new Apache HTTP Server 2.4.37 Service Pack 1 packages that are part of the JBoss Core Services offering.<br>This release serves as a replacement for Red Hat JBoss Core Services Pack Apache Server 2.4.37 and includes bug fixes and enhancements. Refer to the Release Notes for information on the most significant bug fixes and enhancements included in this release.<br>Security fix(es):<br><li> httpd: URL normalization inconsistency (CVE-2019-0220)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
This release adds the new Apache HTTP Server 2.4.29 Service Pack 3 packages that are part of the JBoss Core Services offering.<br>This release serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.29 SP2, and includes security and bug fixes. Refer to the Release Notes for information on the component upgrades included in this release.<br>Security Fix(es):<br><li> modhttp2: HTTP/2: 0-length headers leads to denial of service (CVE-2019-9516)</li> <li> modhttp2: HTTP/2: request for large response leads to denial of service (CVE-2019-9517)</li> Bug Fix(es):<br><li> nghttp2: Rebase to 1.39.2</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products, and is packaged under Red Hat JBoss Core Services to allow for faster distribution of updates, and for a more consistent update experience.<br>This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.51 Service Pack 2 serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.51 Service Pack 1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> apr-util: out-of-bounds writes in the aprbase64 (CVE-2022-25147)</li> <li> expat: use-after free caused by overeager destruction of a shared DTD in XMLExternalEntityParserCreate (CVE-2022-43680)</li> <li> curl: HSTS bypass via IDN (CVE-2022-43551)</li> <li> curl: HTTP Proxy deny use-after-free (CVE-2022-43552)</li> <li> curl: HSTS ignored on multiple requests (CVE-2023-23914)</li> <li> curl: HSTS amnesia with --parallel (CVE-2023-23915)</li> <li> curl: HTTP multi-header compression denial of service (CVE-2023-23916)</li> <li> curl: TELNET option IAC injection (CVE-2023-27533)</li> <li> curl: SFTP path ~ resolving discrepancy (CVE-2023-27534)</li> <li> expat: use-after free caused by overeager destruction of a shared DTD in XMLExternalEntityParserCreate (CVE-2022-43680)</li> <li> httpd: moddav: out-of-bounds read/write of zero byte (CVE-2006-20001)</li> <li> httpd: HTTP request splitting with modrewrite and modproxy (CVE-2023-25690)</li> <li> openssl: timing attack in RSA Decryption implementation (CVE-2022-4304)</li> <li> openssl: double free after calling PEMreadbioex (CVE-2022-4450)</li> <li> openssl: use-after-free following BIOnewNDEF (CVE-2023-0215)</li> <li> openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.