Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP10 security update
🔗 CVE IDs covered (13)
📋 Description
CVE-2019-17567 — httpd: mod_proxy_wstunnel tunneling of non Upgraded connection CVE-2019-20838 — pcre: Buffer over-read in JIT when UTF is disabled and \X or \R has fixed quantifier greater than 1 CVE-2020-13950 — httpd: mod_proxy NULL pointer dereference CVE-2020-14155 — pcre: Integer overflow when parsing callout numeric arguments CVE-2020-35452 — httpd: Single zero byte stack overflow in mod_auth_digest CVE-2021-3688 — JBCS: URL normalization issue with dot-dot-semicolon(s) leads to information disclosure CVE-2021-3712 — openssl: Read buffer overruns processing ASN.1 strings CVE-2021-23840 — openssl: integer overflow in CipherUpdate CVE-2021-23841 — openssl: NULL pointer dereference in X509_issuer_and_serial_hash() CVE-2021-26690 — httpd: mod_session: NULL pointer dereference when parsing Cookie header CVE-2021-26691 — httpd: mod_session: Heap overflow via a crafted SessionHeader value CVE-2021-30641 — httpd: Unexpected URL matching with 'MergeSlashes OFF' CVE-2021-34798 — httpd: NULL pointer dereference via malformed requests
🎯 Affected products144
- Red Hat JBoss Core Services on RHEL 7 Server
- Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-0:1.6.3-107.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-0:1.6.3-107.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-0:1.6.3-107.jbcs.el7.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-0:1.6.3-107.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-debuginfo-0:1.6.3-107.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-debuginfo-0:1.6.3-107.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-devel-0:1.6.3-107.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-devel-0:1.6.3-107.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-0:1.6.1-84.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-0:1.6.1-84.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-0:1.6.1-84.jbcs.el7.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-0:1.6.1-84.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-debuginfo-0:1.6.1-84.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-debuginfo-0:1.6.1-84.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-devel-0:1.6.1-84.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-devel-0:1.6.1-84.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-ldap-0:1.6.1-84.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-ldap-0:1.6.1-84.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-ldap-debuginfo-0:1.6.1-84.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-mysql-0:1.6.1-84.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-mysql-0:1.6.1-84.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-mysql-debuginfo-0:1.6.1-84.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-nss-0:1.6.1-84.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-nss-0:1.6.1-84.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-nss-debuginfo-0:1.6.1-84.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-odbc-0:1.6.1-84.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-odbc-0:1.6.1-84.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-odbc-debuginfo-0:1.6.1-84.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- +114 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Only configurations which use mod_proxy_wstunnel are affected by this flaw. It is also safe to comment-out the "LoadModule proxy_wstunnel_module ... " line in /etc/httpd/conf.modules.d/00-proxy.conf for configurations which do not rely on a websockets reverse proxy. Workaround: Do not use more than one fixed quantifier with \R or \X with UTF disabled in PCRE or PCRE2, as these are the conditions needed to trigger the flaw. Workaround: This flaw can be mitigated by not compiling regular expressions with a callout value greater outside of 0-255 or handling the value passed to the callback within the application code. Workaround: Only configurations which use mod_auth_digest are affected by this flaw. Also as per upstream this flaw is not exploitable in most conditions, so there should really be no impact of this flaw. Workaround: Manually add LocationMatch directive to deny any possible problem requests in the JBCS httpd configuration. For example: ~~~ <LocationMatch ".*\.\.;.*"> Require all denied </LocationMatch> ~~~ Workaround: Customers should make an attempt to run current binaries/architectures and not rely on compatibility layers to run older binaries/architectures. In case older binaries/architectures are needed, sandboxing should be used to address such problems and guard the bug. Workaround: As per upstream "The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources." Workaround: Only configurations which use the "SessionEnv" directive (which is not widely used) are vulnerable to this flaw. SessionEnv is not enabled in default configuration of httpd package shipped with Red Hat Products. Workaround: This issue can be mitigated by setting the "MergeSlashes" directive to OFF Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2021:4614
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1848436
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1848444
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1930310
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1930324
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1966724
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1966729
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1966732
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1966738
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1966740
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1966743
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1995634
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_4614.json