RHSA-2019:3932
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Security Release on RHEL 6
CVSS Metrics
- v3.0•HIGH•Score: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Systems
- redhat•jbcs-httpd24-apr
< 0:1.6.3-63.jbcs.el6
- redhat•jbcs-httpd24-apr-debuginfo
< 0:1.6.3-63.jbcs.el6
- redhat•jbcs-httpd24-apr-devel
< 0:1.6.3-63.jbcs.el6
- redhat•jbcs-httpd24-apr-util
< 0:1.6.1-48.jbcs.el6
- redhat•jbcs-httpd24-apr-util-debuginfo
< 0:1.6.1-48.jbcs.el6
- redhat•jbcs-httpd24-apr-util-devel
< 0:1.6.1-48.jbcs.el6
- redhat•jbcs-httpd24-apr-util-ldap
< 0:1.6.1-48.jbcs.el6
- redhat•jbcs-httpd24-apr-util-mysql
< 0:1.6.1-48.jbcs.el6
- redhat•jbcs-httpd24-apr-util-nss
< 0:1.6.1-48.jbcs.el6
- redhat•jbcs-httpd24-apr-util-odbc
< 0:1.6.1-48.jbcs.el6
- redhat•jbcs-httpd24-apr-util-openssl
< 0:1.6.1-48.jbcs.el6
- redhat•jbcs-httpd24-apr-util-pgsql
< 0:1.6.1-48.jbcs.el6
- redhat•jbcs-httpd24-apr-util-sqlite
< 0:1.6.1-48.jbcs.el6
- redhat•jbcs-httpd24-brotli
< 0:1.0.6-7.jbcs.el6
- redhat•jbcs-httpd24-brotli-debuginfo
< 0:1.0.6-7.jbcs.el6
- redhat•jbcs-httpd24-brotli-devel
< 0:1.0.6-7.jbcs.el6
- redhat•jbcs-httpd24-curl
< 0:7.64.1-14.jbcs.el6
- redhat•jbcs-httpd24-curl-debuginfo
< 0:7.64.1-14.jbcs.el6
- redhat•jbcs-httpd24-httpd
< 0:2.4.37-33.jbcs.el6
- redhat•jbcs-httpd24-httpd-debuginfo
< 0:2.4.37-33.jbcs.el6
- redhat•jbcs-httpd24-httpd-devel
< 0:2.4.37-33.jbcs.el6
- redhat•jbcs-httpd24-httpd-manual
< 0:2.4.37-33.jbcs.el6
- redhat•jbcs-httpd24-httpd-selinux
< 0:2.4.37-33.jbcs.el6
- redhat•jbcs-httpd24-httpd-tools
< 0:2.4.37-33.jbcs.el6
- redhat•jbcs-httpd24-jansson
< 0:2.11-20.jbcs.el6
- redhat•jbcs-httpd24-jansson-debuginfo
< 0:2.11-20.jbcs.el6
- redhat•jbcs-httpd24-jansson-devel
< 0:2.11-20.jbcs.el6
- redhat•jbcs-httpd24-libcurl
< 0:7.64.1-14.jbcs.el6
- redhat•jbcs-httpd24-libcurl-devel
< 0:7.64.1-14.jbcs.el6
- redhat•jbcs-httpd24-mod_cluster-native
< 0:1.3.12-9.Final_redhat_2.jbcs.el6
- redhat•jbcs-httpd24-mod_cluster-native-debuginfo
< 0:1.3.12-9.Final_redhat_2.jbcs.el6
- redhat•jbcs-httpd24-mod_jk
< 0:1.2.46-22.redhat_1.jbcs.el6
- redhat•jbcs-httpd24-mod_jk-ap24
< 0:1.2.46-22.redhat_1.jbcs.el6
- redhat•jbcs-httpd24-mod_jk-debuginfo
< 0:1.2.46-22.redhat_1.jbcs.el6
- redhat•jbcs-httpd24-mod_jk-manual
< 0:1.2.46-22.redhat_1.jbcs.el6
- redhat•jbcs-httpd24-mod_ldap
< 0:2.4.37-33.jbcs.el6
- redhat•jbcs-httpd24-mod_md
< 0:2.4.37-33.jbcs.el6
- redhat•jbcs-httpd24-mod_proxy_html
< 1:2.4.37-33.jbcs.el6
- redhat•jbcs-httpd24-mod_security
< 0:2.9.2-16.GA.jbcs.el6
- redhat•jbcs-httpd24-mod_security-debuginfo
< 0:2.9.2-16.GA.jbcs.el6
- redhat•jbcs-httpd24-mod_session
< 0:2.4.37-33.jbcs.el6
- redhat•jbcs-httpd24-mod_ssl
< 1:2.4.37-33.jbcs.el6
- redhat•jbcs-httpd24-nghttp2
< 0:1.39.2-4.jbcs.el6
- redhat•jbcs-httpd24-nghttp2-debuginfo
< 0:1.39.2-4.jbcs.el6
- redhat•jbcs-httpd24-nghttp2-devel
< 0:1.39.2-4.jbcs.el6
- redhat•jbcs-httpd24-openssl
< 1:1.1.1-25.jbcs.el6
- redhat•jbcs-httpd24-openssl-debuginfo
< 1:1.1.1-25.jbcs.el6
- redhat•jbcs-httpd24-openssl-devel
< 1:1.1.1-25.jbcs.el6
- redhat•jbcs-httpd24-openssl-libs
< 1:1.1.1-25.jbcs.el6
- redhat•jbcs-httpd24-openssl-perl
< 1:1.1.1-25.jbcs.el6
Showing first 50 affected entries in server-rendered view.
References (64)
- https://access.redhat.com/errata/RHSA-2019:3932
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=1568253
- https://bugzilla.redhat.com/show_bug.cgi?id=1644364
- https://bugzilla.redhat.com/show_bug.cgi?id=1645695
- https://bugzilla.redhat.com/show_bug.cgi?id=1668493
- https://bugzilla.redhat.com/show_bug.cgi?id=1668497
- https://bugzilla.redhat.com/show_bug.cgi?id=1695020
- https://bugzilla.redhat.com/show_bug.cgi?id=1695030
- https://bugzilla.redhat.com/show_bug.cgi?id=1695042
- https://bugzilla.redhat.com/show_bug.cgi?id=1735741
- https://bugzilla.redhat.com/show_bug.cgi?id=1741860
- https://bugzilla.redhat.com/show_bug.cgi?id=1741864
- https://bugzilla.redhat.com/show_bug.cgi?id=1741868
- https://issues.redhat.com/browse/JBCS-798
- https://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_3932.json
- https://access.redhat.com/security/cve/CVE-2018-0734
- https://www.cve.org/CVERecord?id=CVE-2018-0734
- https://nvd.nist.gov/vuln/detail/CVE-2018-0734
- https://access.redhat.com/security/cve/CVE-2018-0737
- https://www.cve.org/CVERecord?id=CVE-2018-0737
- https://nvd.nist.gov/vuln/detail/CVE-2018-0737
- http://www.openwall.com/lists/oss-security/2018/04/16/3
- https://www.openssl.org/news/secadv/20180416.txt
- https://access.redhat.com/security/cve/CVE-2018-5407
- https://www.cve.org/CVERecord?id=CVE-2018-5407
- https://nvd.nist.gov/vuln/detail/CVE-2018-5407
- https://github.com/bbbrumley/portsmash
- https://www.openssl.org/news/secadv/20181112.txt
- https://access.redhat.com/security/cve/CVE-2018-17189
- https://www.cve.org/CVERecord?id=CVE-2018-17189
- https://nvd.nist.gov/vuln/detail/CVE-2018-17189
- https://access.redhat.com/security/cve/CVE-2018-17199
- https://www.cve.org/CVERecord?id=CVE-2018-17199
- https://nvd.nist.gov/vuln/detail/CVE-2018-17199
- https://access.redhat.com/security/cve/CVE-2019-0196
- https://www.cve.org/CVERecord?id=CVE-2019-0196
- https://nvd.nist.gov/vuln/detail/CVE-2019-0196
- http://www.apache.org/dist/httpd/CHANGES_2.4
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://access.redhat.com/security/cve/CVE-2019-0197
- https://www.cve.org/CVERecord?id=CVE-2019-0197
- https://nvd.nist.gov/vuln/detail/CVE-2019-0197
- https://access.redhat.com/security/cve/CVE-2019-0217
- https://www.cve.org/CVERecord?id=CVE-2019-0217
- https://nvd.nist.gov/vuln/detail/CVE-2019-0217
- https://access.redhat.com/security/cve/CVE-2019-9511
- https://www.cve.org/CVERecord?id=CVE-2019-9511
- https://nvd.nist.gov/vuln/detail/CVE-2019-9511
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
- https://kb.cert.org/vuls/id/605641/
- https://nodejs.org/en/blog/vulnerability/aug-2019-security-releases/
- https://www.nginx.com/blog/nginx-updates-mitigate-august-2019-http-2-vulnerabilities/
- https://access.redhat.com/security/cve/CVE-2019-9513
- https://www.cve.org/CVERecord?id=CVE-2019-9513
- https://nvd.nist.gov/vuln/detail/CVE-2019-9513
- https://nghttp2.org/blog/2019/08/19/nghttp2-v1-39-2/
- https://access.redhat.com/security/cve/CVE-2019-9516
- https://www.cve.org/CVERecord?id=CVE-2019-9516
- https://nvd.nist.gov/vuln/detail/CVE-2019-9516
- https://github.com/nghttp2/nghttp2/issues/1382#
- https://access.redhat.com/security/cve/CVE-2019-9517
- https://www.cve.org/CVERecord?id=CVE-2019-9517
- https://nvd.nist.gov/vuln/detail/CVE-2019-9517