RHSA-2017:2708HighCVSS 7.5
Red Hat Security Advisory: Red Hat JBoss Core Services security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2015-3185 — httpd: ap_some_auth_required() does not properly indicate authenticated request in 2.4 CVE-2016-2183 — SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) CVE-2017-9788 — httpd: Uninitialized memory reflection in mod_auth_digest
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2017:2708
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=core.service.apachehttp&downloadType=securityPatches&version=2.4.23
- externalhttps://access.redhat.com/documentation/en/red-hat-jboss-core-services/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1243888
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1369383
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1470748
- externalhttps://issues.redhat.com/browse/JBCS-329
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2017/rhsa-2017_2708.json