Red Hat Security Advisory: rhvm-appliance security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2018-1067 — undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) CVE-2018-1114 — undertow: File descriptor leak caused by JarURLConnection.getLastModified() allows attacker to cause a denial of service CVE-2018-8039 — apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.* CVE-2018-10237 — guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service CVE-2018-10862 — wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip) CVE-2018-10915 — postgresql: Certain host connection parameters defeat client-side security defenses CVE-2018-1000180 — bouncycastle: flaw in the low-level interface to RSA key pair generator
🎯 Affected products6
- Red Hat Virtualization 4 Hypervisor for RHEL 7
- Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
- rhvm-appliance-2:4.2-20180828.0.el7.noarch as a component of Red Hat Virtualization 4 Hypervisor for RHEL 7
- rhvm-appliance-2:4.2-20180828.0.el7.noarch as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
- rhvm-appliance-2:4.2-20180828.0.el7.src as a component of Red Hat Virtualization 4 Hypervisor for RHEL 7
- rhvm-appliance-2:4.2-20180828.0.el7.src as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2018:2643
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1550671
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1573045
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1573391
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1588306
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1593527
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1595332
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1609891
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1616249
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_2643.json