Описание
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.
It was discovered that it is possible to remotely Segfault Apache http server with a specially crafted string sent to the mod_cluster via service messages (MCMP).
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Enterprise Web Server 3 | mod_cluster | Affected | ||
| Red Hat JBoss Enterprise Application Platform 6.4 | mod_cluster | Fixed | RHSA-2016:2056 | 12.10.2016 |
| Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 | hornetq-native | Fixed | RHSA-2016:2055 | 12.10.2016 |
| Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 | httpd | Fixed | RHSA-2016:2055 | 12.10.2016 |
| Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 | jbcs-httpd24 | Fixed | RHSA-2016:2055 | 12.10.2016 |
| Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 | jbcs-httpd24-openssl | Fixed | RHSA-2016:2055 | 12.10.2016 |
| Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 | mod_cluster-native | Fixed | RHSA-2016:2055 | 12.10.2016 |
| Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 | mod_jk | Fixed | RHSA-2016:2055 | 12.10.2016 |
| Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 | tomcat-native | Fixed | RHSA-2016:2055 | 12.10.2016 |
| Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 | hornetq-native | Fixed | RHSA-2016:2054 | 12.10.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.1 Medium
CVSS3
4.7 Medium
CVSS2
Связанные уязвимости
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote at ...
EPSS
5.1 Medium
CVSS3
4.7 Medium
CVSS2