Red Hat Security Advisory: Satellite 6.14.2 Async Security Update
🔗 CVE IDs covered (10)
📋 Description
CVE-2023-0809 — mosquitto: memory leak leads to unresponsive broker CVE-2023-3592 — mosquitto: memory leak leads to unresponsive broker CVE-2023-4785 — gRPC: file descriptor exhaustion leads to denial of service CVE-2023-26049 — jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies CVE-2023-26141 — sidekiq: DoS in dashboard-charts CVE-2023-28366 — mosquitto: memory leak leads to unresponsive broker CVE-2023-36479 — jetty: Improper addition of quotation marks to user inputs in CgiServlet CVE-2023-38545 — curl: heap based buffer overflow in the SOCKS5 proxy handshake CVE-2023-40167 — jetty: Improper validation of HTTP/1 content-length CVE-2023-40175 — rubygem-puma: HTTP request smuggling when parsing chunked transfer encoding bodies and zero-length content-length headers
🎯 Affected products57
- Red Hat Satellite 6.14 for RHEL 8
- candlepin-0:4.3.11-1.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- candlepin-0:4.3.11-1.el8sat.src as a component of Red Hat Satellite 6.14 for RHEL 8
- candlepin-selinux-0:4.3.11-1.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-0:3.7.0.11-2.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-0:3.7.0.11-2.el8sat.src as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-cli-0:3.7.0.11-2.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-debug-0:3.7.0.11-2.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-dynflow-sidekiq-0:3.7.0.11-2.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-ec2-0:3.7.0.11-2.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-installer-1:3.7.0.7-1.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-installer-1:3.7.0.7-1.el8sat.src as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-installer-katello-1:3.7.0.7-1.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-journald-0:3.7.0.11-2.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-libvirt-0:3.7.0.11-2.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-openstack-0:3.7.0.11-2.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-ovirt-0:3.7.0.11-2.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-postgresql-0:3.7.0.11-2.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-redis-0:3.7.0.11-2.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-service-0:3.7.0.11-2.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-telemetry-0:3.7.0.11-2.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- foreman-vmware-0:3.7.0.11-2.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- mosquitto-0:2.0.17-1.el8sat.src as a component of Red Hat Satellite 6.14 for RHEL 8
- mosquitto-0:2.0.17-1.el8sat.x86_64 as a component of Red Hat Satellite 6.14 for RHEL 8
- mosquitto-debuginfo-0:2.0.17-1.el8sat.x86_64 as a component of Red Hat Satellite 6.14 for RHEL 8
- mosquitto-debugsource-0:2.0.17-1.el8sat.x86_64 as a component of Red Hat Satellite 6.14 for RHEL 8
- puppet-agent-0:7.27.0-1.el8sat.src as a component of Red Hat Satellite 6.14 for RHEL 8
- puppet-agent-0:7.27.0-1.el8sat.x86_64 as a component of Red Hat Satellite 6.14 for RHEL 8
- puppetserver-0:7.14.0-1.el8sat.noarch as a component of Red Hat Satellite 6.14 for RHEL 8
- puppetserver-0:7.14.0-1.el8sat.src as a component of Red Hat Satellite 6.14 for RHEL 8
- +27 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To avoid this issue, we recommend you do not use `CURLPROXY_SOCKS5_HOSTNAME` proxies with curl. Also do not set a proxy environment variable to socks5h://
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2024:0797
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_satellite/6.14/html/upgrading_and_updating_red_hat_satellite/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2232729
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2236341
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2236882
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239010
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239017
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239630
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239634
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2241933
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2250347
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254974
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255260
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257321
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257324
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257326
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257327
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257329
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257330
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257331
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257332
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257415
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2260525
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262131
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0797.json