RHSA-2021:3741HighCVSS 7.5
Red Hat Security Advisory: Red Hat JBoss Web Server 5.5.1 Security Update
🔗 CVE IDs covered (1)
📋 Description
CVE-2021-41079 — tomcat: Infinite loop while reading an unexpected TLS packet when using OpenSSL JSSE engine
🎯 Affected products26
- Red Hat JBoss Web Server 5.5 for RHEL 7 Server
- Red Hat JBoss Web Server 5.5 for RHEL 8
- jws5-tomcat-0:9.0.43-13.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 7 Server
- jws5-tomcat-0:9.0.43-13.redhat_00013.1.el7jws.src as a component of Red Hat JBoss Web Server 5.5 for RHEL 7 Server
- jws5-tomcat-0:9.0.43-13.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 8
- jws5-tomcat-0:9.0.43-13.redhat_00013.1.el8jws.src as a component of Red Hat JBoss Web Server 5.5 for RHEL 8
- jws5-tomcat-admin-webapps-0:9.0.43-13.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 7 Server
- jws5-tomcat-admin-webapps-0:9.0.43-13.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 8
- jws5-tomcat-docs-webapp-0:9.0.43-13.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 7 Server
- jws5-tomcat-docs-webapp-0:9.0.43-13.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 8
- jws5-tomcat-el-3.0-api-0:9.0.43-13.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 7 Server
- jws5-tomcat-el-3.0-api-0:9.0.43-13.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 8
- jws5-tomcat-java-jdk11-0:9.0.43-13.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 7 Server
- jws5-tomcat-java-jdk8-0:9.0.43-13.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 7 Server
- jws5-tomcat-javadoc-0:9.0.43-13.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 7 Server
- jws5-tomcat-javadoc-0:9.0.43-13.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 8
- jws5-tomcat-jsp-2.3-api-0:9.0.43-13.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 7 Server
- jws5-tomcat-jsp-2.3-api-0:9.0.43-13.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 8
- jws5-tomcat-lib-0:9.0.43-13.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 7 Server
- jws5-tomcat-lib-0:9.0.43-13.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 8
- jws5-tomcat-selinux-0:9.0.43-13.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 7 Server
- jws5-tomcat-selinux-0:9.0.43-13.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 8
- jws5-tomcat-servlet-4.0-api-0:9.0.43-13.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 7 Server
- jws5-tomcat-servlet-4.0-api-0:9.0.43-13.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 8
- jws5-tomcat-webapps-0:9.0.43-13.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 7 Server
- jws5-tomcat-webapps-0:9.0.43-13.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.5 for RHEL 8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258