Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP11 security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2021-3516 — libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c CVE-2021-3517 — libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c CVE-2021-3518 — libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c CVE-2021-3537 — libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode CVE-2021-3541 — libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms CVE-2022-0778 — openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates CVE-2022-22720 — httpd: Errors encountered during the discarding of request body lead to HTTP request smuggling CVE-2022-23308 — libxml2: Use-after-free of ID and IDREF attributes
🎯 Affected products136
- Red Hat JBoss Core Services on RHEL 7 Server
- Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-0:1.6.1-91.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-0:1.6.1-91.jbcs.el7.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-0:1.6.1-91.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-debuginfo-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-debuginfo-0:1.6.1-91.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-devel-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-devel-0:1.6.1-91.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-ldap-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-ldap-0:1.6.1-91.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-ldap-debuginfo-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-mysql-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-mysql-0:1.6.1-91.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-mysql-debuginfo-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-nss-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-nss-0:1.6.1-91.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-nss-debuginfo-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-odbc-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-odbc-0:1.6.1-91.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-odbc-debuginfo-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-openssl-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-openssl-0:1.6.1-91.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-openssl-debuginfo-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-pgsql-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-pgsql-0:1.6.1-91.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-pgsql-debuginfo-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-sqlite-0:1.6.1-91.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-sqlite-0:1.6.1-91.jbcs.el7.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- +106 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: This flaw can be mitigated by not using xmllint with the --html and --push options together. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: There are currently no known mitigations for this issue.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2022:1389
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1950515
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1954225
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1954232
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1954242
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1956522
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056913
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2062202
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064321
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1389.json