Red Hat Security Advisory: Red Hat JBoss Web Server 5.6.0 Security release
🔗 CVE IDs covered (6)
📋 Description
CVE-2021-3712 — openssl: Read buffer overruns processing ASN.1 strings CVE-2021-23840 — openssl: integer overflow in CipherUpdate CVE-2021-23841 — openssl: NULL pointer dereference in X509_issuer_and_serial_hash() CVE-2021-30640 — tomcat: JNDI realm authentication weakness CVE-2021-33037 — tomcat: HTTP request smuggling when used with a reverse proxy CVE-2021-42340 — tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS
🎯 Affected products1
- Red Hat JBoss Web Server 5
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. Workaround: Customers should make an attempt to run current binaries/architectures and not rely on compatibility layers to run older binaries/architectures. In case older binaries/architectures are needed, sandboxing should be used to address such problems and guard the bug. Workaround: As per upstream "The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources."
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2021:4863
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981533
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981544
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2014356
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_4863.json