RHSA-2018:2643HighCVSS 8.5

Red Hat Security Advisory: rhvm-appliance security update

Published
September 4, 2018
Last Modified
August 4, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2018-1067 — undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) CVE-2018-1114 — undertow: File descriptor leak caused by JarURLConnection.getLastModified() allows attacker to cause a denial of service CVE-2018-8039 — apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.* CVE-2018-10237 — guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service CVE-2018-10862 — wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip) CVE-2018-10915 — postgresql: Certain host connection parameters defeat client-side security defenses CVE-2018-1000180 — bouncycastle: flaw in the low-level interface to RSA key pair generator

🎯 Affected products6

  • Red Hat Virtualization 4 Hypervisor for RHEL 7
  • Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
  • rhvm-appliance-2:4.2-20180828.0.el7.noarch as a component of Red Hat Virtualization 4 Hypervisor for RHEL 7
  • rhvm-appliance-2:4.2-20180828.0.el7.noarch as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
  • rhvm-appliance-2:4.2-20180828.0.el7.src as a component of Red Hat Virtualization 4 Hypervisor for RHEL 7
  • rhvm-appliance-2:4.2-20180828.0.el7.src as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891

🔗 References (11)