exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Red Hat Security Advisory 2023-4629-01

Red Hat Security Advisory 2023-4629-01
Posted Aug 16, 2023
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2023-4629-01 - Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products and packaged under Red Hat JBoss Core Services, to allow for faster distribution of updates and for a more consistent update experience. This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.57 serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.51 Service Pack 2, and includes bug fixes and enhancements, which are documented in the Release Notes linked to in the References section. Issues addressed include HTTP response splitting, bypass, integer overflow, and use-after-free vulnerabilities.

tags | advisory, web, overflow, vulnerability
systems | linux, redhat
advisories | CVE-2022-24963, CVE-2022-36760, CVE-2022-37436, CVE-2022-48279, CVE-2023-24021, CVE-2023-27522, CVE-2023-28319, CVE-2023-28321, CVE-2023-28322
SHA-256 | 6c109e8112c245ff647417e707926d11d65d612b66e7ae46f1f05cb3ab724077

Red Hat Security Advisory 2023-4629-01

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
Red Hat Security Advisory

Synopsis: Moderate: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 security update
Advisory ID: RHSA-2023:4629-01
Product: Red Hat JBoss Core Services
Advisory URL: https://access.redhat.com/errata/RHSA-2023:4629
Issue date: 2023-08-15
CVE Names: CVE-2022-24963 CVE-2022-36760 CVE-2022-37436
CVE-2022-48279 CVE-2023-24021 CVE-2023-27522
CVE-2023-28319 CVE-2023-28321 CVE-2023-28322
=====================================================================

1. Summary:

An update is now available for Red Hat JBoss Core Services.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat JBoss Core Services on RHEL 7 Server - noarch, x86_64
Red Hat JBoss Core Services on RHEL 8 - noarch, x86_64

3. Description:

Red Hat JBoss Core Services is a set of supplementary software for Red Hat
JBoss middleware products. This software, such as Apache HTTP Server, is
common to multiple JBoss middleware products and packaged under Red Hat
JBoss Core Services, to allow for faster distribution of updates and for a
more consistent update experience.

This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.57
serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server
2.4.51 Service Pack 2, and includes bug fixes and enhancements, which are
documented in the Release Notes linked to in the References section.

Security Fix(es):

* apr-util: integer overflow/wraparound in apr_encode (CVE-2022-24963)

* httpd: mod_proxy_ajp: Possible request smuggling (CVE-2022-36760)

* httpd: mod_proxy: HTTP response splitting (CVE-2022-37436)

* mod_security: incorrect parsing of HTTP multipart requests leads to web
application firewall bypass (CVE-2022-48279)

* modsecurity: lacking the complete content in FILES_TMP_CONTENT leads to
web application firewall bypass (CVE-2023-24021)

* httpd: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)

* curl: use after free in SSH sha256 fingerprint check (CVE-2023-28319)

* curl: IDN wildcard match may lead to Improper Cerificate Validation
(CVE-2023-28321)

* curl: more POST-after-PUT confusion (CVE-2023-28322)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

2161773 - CVE-2022-37436 httpd: mod_proxy: HTTP response splitting
2161777 - CVE-2022-36760 httpd: mod_proxy_ajp: Possible request smuggling
2163615 - CVE-2023-24021 modsecurity: lacking the complete content in FILES_TMP_CONTENT leads to web application firewall bypass
2163622 - CVE-2022-48279 mod_security: incorrect parsing of HTTP multipart requests leads to web application firewall bypass
2169465 - CVE-2022-24963 apr: integer overflow/wraparound in apr_encode
2176211 - CVE-2023-27522 httpd: mod_proxy_uwsgi HTTP response splitting
2196778 - CVE-2023-28319 curl: use after free in SSH sha256 fingerprint check
2196786 - CVE-2023-28321 curl: IDN wildcard match may lead to Improper Cerificate Validation
2196793 - CVE-2023-28322 curl: more POST-after-PUT confusion

6. Package List:

Red Hat JBoss Core Services on RHEL 7 Server:

Source:
jbcs-httpd24-apr-1.7.0-8.el7jbcs.src.rpm
jbcs-httpd24-apr-util-1.6.1-102.el7jbcs.src.rpm
jbcs-httpd24-curl-8.2.1-1.el7jbcs.src.rpm
jbcs-httpd24-httpd-2.4.57-5.el7jbcs.src.rpm
jbcs-httpd24-mod_http2-1.15.19-28.el7jbcs.src.rpm
jbcs-httpd24-mod_jk-1.2.48-51.redhat_1.el7jbcs.src.rpm
jbcs-httpd24-mod_md-2.4.0-25.el7jbcs.src.rpm
jbcs-httpd24-mod_proxy_cluster-1.3.19-4.el7jbcs.src.rpm
jbcs-httpd24-mod_security-2.9.3-29.el7jbcs.src.rpm

noarch:
jbcs-httpd24-httpd-manual-2.4.57-5.el7jbcs.noarch.rpm

x86_64:
jbcs-httpd24-apr-1.7.0-8.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-debuginfo-1.7.0-8.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-devel-1.7.0-8.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-debuginfo-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-devel-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-ldap-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-mysql-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-nss-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-odbc-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-openssl-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-pgsql-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-apr-util-sqlite-1.6.1-102.el7jbcs.x86_64.rpm
jbcs-httpd24-curl-8.2.1-1.el7jbcs.x86_64.rpm
jbcs-httpd24-curl-debuginfo-8.2.1-1.el7jbcs.x86_64.rpm
jbcs-httpd24-httpd-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-httpd-debuginfo-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-httpd-devel-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-httpd-selinux-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-httpd-tools-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-libcurl-8.2.1-1.el7jbcs.x86_64.rpm
jbcs-httpd24-libcurl-devel-8.2.1-1.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_http2-1.15.19-28.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_http2-debuginfo-1.15.19-28.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_jk-ap24-1.2.48-51.redhat_1.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_jk-debuginfo-1.2.48-51.redhat_1.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_ldap-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_md-2.4.0-25.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_md-debuginfo-2.4.0-25.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_cluster-1.3.19-4.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_cluster-debuginfo-1.3.19-4.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_html-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_security-2.9.3-29.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_security-debuginfo-2.9.3-29.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_session-2.4.57-5.el7jbcs.x86_64.rpm
jbcs-httpd24-mod_ssl-2.4.57-5.el7jbcs.x86_64.rpm

Red Hat JBoss Core Services on RHEL 8:

Source:
jbcs-httpd24-apr-1.7.0-8.el8jbcs.src.rpm
jbcs-httpd24-apr-util-1.6.1-102.el8jbcs.src.rpm
jbcs-httpd24-curl-8.2.1-1.el8jbcs.src.rpm
jbcs-httpd24-httpd-2.4.57-5.el8jbcs.src.rpm
jbcs-httpd24-mod_http2-1.15.19-28.el8jbcs.src.rpm
jbcs-httpd24-mod_jk-1.2.48-51.redhat_1.el8jbcs.src.rpm
jbcs-httpd24-mod_md-2.4.0-25.el8jbcs.src.rpm
jbcs-httpd24-mod_proxy_cluster-1.3.19-4.el8jbcs.src.rpm
jbcs-httpd24-mod_security-2.9.3-29.el8jbcs.src.rpm

noarch:
jbcs-httpd24-httpd-manual-2.4.57-5.el8jbcs.noarch.rpm

x86_64:
jbcs-httpd24-apr-1.7.0-8.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-debuginfo-1.7.0-8.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-devel-1.7.0-8.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-devel-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-ldap-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-ldap-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-mysql-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-mysql-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-nss-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-nss-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-odbc-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-odbc-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-openssl-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-openssl-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-pgsql-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-pgsql-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-sqlite-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-apr-util-sqlite-debuginfo-1.6.1-102.el8jbcs.x86_64.rpm
jbcs-httpd24-curl-8.2.1-1.el8jbcs.x86_64.rpm
jbcs-httpd24-curl-debuginfo-8.2.1-1.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-debuginfo-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-devel-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-selinux-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-tools-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-httpd-tools-debuginfo-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-libcurl-8.2.1-1.el8jbcs.x86_64.rpm
jbcs-httpd24-libcurl-debuginfo-8.2.1-1.el8jbcs.x86_64.rpm
jbcs-httpd24-libcurl-devel-8.2.1-1.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_http2-1.15.19-28.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_http2-debuginfo-1.15.19-28.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_jk-ap24-1.2.48-51.redhat_1.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_jk-ap24-debuginfo-1.2.48-51.redhat_1.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_ldap-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_ldap-debuginfo-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_md-2.4.0-25.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_md-debuginfo-2.4.0-25.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_cluster-1.3.19-4.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_cluster-debuginfo-1.3.19-4.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_html-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_proxy_html-debuginfo-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_security-2.9.3-29.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_security-debuginfo-2.9.3-29.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_session-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_session-debuginfo-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_ssl-2.4.57-5.el8jbcs.x86_64.rpm
jbcs-httpd24-mod_ssl-debuginfo-2.4.57-5.el8jbcs.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2022-24963
https://access.redhat.com/security/cve/CVE-2022-36760
https://access.redhat.com/security/cve/CVE-2022-37436
https://access.redhat.com/security/cve/CVE-2022-48279
https://access.redhat.com/security/cve/CVE-2023-24021
https://access.redhat.com/security/cve/CVE-2023-27522
https://access.redhat.com/security/cve/CVE-2023-28319
https://access.redhat.com/security/cve/CVE-2023-28321
https://access.redhat.com/security/cve/CVE-2023-28322
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJk2938AAoJENzjgjWX9erEtTsP/3LmmBo74lDl/6hEmS7CVjrG
tNDPsAWewTMp9k1SOFqRtVY/B5lFTUMP47nAlozHcVwtqfr8hNTRNot0FgrZZJBM
lHqzvNGLZBFSDP4/otKRj37kTi9N2LTBj2CUWok72XbQlxO0Lyqa33XR4LbqMdzk
ZZ/Bx2n6bi8hzGSr2ESXGv+PFl0XsjMZH4XAeU/XOR6kThlOJPAKnl+jzA3r2ip6
EJrOwDM1Kh0oXs6+aVC7aKkqdihRmxbmONzVjv3EGt/CfEoJCf9XmFKfnEugEP8W
EGomu/5iwcYDYoauRR/WGf49MylrOEiqGYkglkbXH5G8iMGpZTuSqnqK0wzdPhgJ
xwDaid3+JPxB0tbtaBpEdH1trYNxrySvVD2XEe8UP5sdft8Ix9tOndHGOgl2P7I2
ws64DPAL32H4TyoiuXAid0tPIsSPzPuBBupW2sMI0LBmKSsiQ83Q3foYXDlLo+FM
V5qtHcsKpeXsyJ27brIMgT2mRm8NL26qGmqsp+u1Jq2xceNzn8H9O2HbVCUQXrXo
RofB2qkwwopjW5T0xun9WRle6uWuzzVQQXidT4zlmt5L6Q5myJ56/LD6mL1sIfRg
BnoZbUpjOxwP2SWNHPZvxCiu0hN7nQUQKzP+kTkeKVOIx60KY/xmK4ROmimVR8lB
K4ikAMvb9gMm7tCnaD5E
=zxHu
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    44 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close