RHSA-2020:2646HighCVSS 7.5

Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP3 security update

Published
June 22, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2018-20843 — expat: large number of colons in input makes parser consume high amount of resources, leading to DoS CVE-2019-0196 — httpd: mod_http2: read-after-free on a string compare CVE-2019-0197 — httpd: mod_http2: possible crash on late upgrade CVE-2019-15903 — expat: heap-based buffer over-read via crafted XML input CVE-2019-19956 — libxml2: memory leak in xmlParseBalancedChunkMemoryRecover in parser.c CVE-2019-20388 — libxml2: memory leak in xmlSchemaPreRun in xmlschemas.c CVE-2020-1934 — httpd: mod_proxy_ftp use of uninitialized value CVE-2020-7595 — libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations CVE-2020-11080 — nghttp2: overly large SETTINGS frames can lead to DoS

🎯 Affected products1

  • Text-Only JBCS

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (15)