RHSA-2017:3113HighCVSS 8.1
Red Hat Security Advisory: Red Hat JBoss Web Server security and bug fix update
🔗 CVE IDs covered (5)
📋 Description
CVE-2016-2183 — SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) CVE-2017-9788 — httpd: Uninitialized memory reflection in mod_auth_digest CVE-2017-9798 — httpd: Use-after-free by limiting unregistered HTTP method (Optionsbleed) CVE-2017-12615 — tomcat: Remote Code Execution via JSP Upload CVE-2017-12617 — tomcat: Remote Code Execution bypass for CVE-2017-12615
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2017:3113
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/articles/3227901
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1369383
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1470748
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1490344
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1493075
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1493220
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1494283
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2017/rhsa-2017_3113.json