Bug 1406822 (CVE-2016-8743)
| Summary: | CVE-2016-8743 httpd: Apache HTTP Request Parsing Whitespace Defects | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Adam Mariš <amaris> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | apmukher, bbaranow, bkundal, bmaxwell, bphinz, cdewolf, csutherl, dandread, dankobrin, darran.lofthouse, dosoudil, fnasser, gzaronik, hhorak, huwang, jason.greene, jawilson, jboss-set, jclere, jkaluza, jorton, lgao, luhliari, mbabacek, mdshaikh, mfrodl, mmilgram, mturk, myarboro, pahan, pgier, pjindal, plodge, pragshar, psakar, pslavice, psotirop, rhel-process-autobot, rmeggins, rnetuka, rsvoboda, sardella, szappis, tgfurnish, tmishler, tschaibl, twalsh, vchlup, vtunka, watson-tool-maintainers, weli, xdmoon, yozone |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | httpd 2.4.25 | Doc Type: | If docs needed, set a value |
| Doc Text: |
It was discovered that the HTTP parser in httpd incorrectly allowed certain characters not permitted by the HTTP protocol specification to appear unencoded in HTTP request headers. If httpd was used in conjunction with a proxy or backend server that interpreted those characters differently, a remote attacker could possibly use this flaw to inject data into HTTP responses, resulting in proxy cache poisoning.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2017-07-11 20:32:58 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1406823, 1412974, 1412975, 1412976, 1425463, 1427675, 1448328, 1448329 | ||
| Bug Blocks: | 1406828, 1457678 | ||
|
Description
Adam Mariš
2016-12-21 15:01:58 UTC
Created httpd tracking bugs for this issue: Affects: fedora-all [bug 1406823] I realize that backporting the upstream fix is non-trivial, but is there any kind of status update that you can provide regarding a potential errata release date? The status is still marked as "NEW", which implies that it's not even being worked on... Thanks in advance. Dear Brian, please check bugs for RHEL-7, RHEL-7 Z-stream and RHEL-6. They are all in modified state. I've finished backporting and QE should now take care of it. This is just tracking bug. Thanks for understanding. I am unable to access any of the related bugs for this to see what is going on. Can someone working this issue post a status update here? Thanks Hi Dan, what exactly would you like to learn? If you seek support, use the Customer Portal, please. If you are coming from the community, you could find all pertinent information here [1] and a small clarification here [2]. Cheers -K- [1] https://httpd.apache.org/security/vulnerabilities_24.html [2] https://bz.apache.org/bugzilla/show_bug.cgi?id=60783 (In reply to Michal Karm Babacek from comment #12) > Hi Dan, what exactly would you like to learn? > > If you seek support, use the Customer Portal, please. > > If you are coming from the community, you could find all pertinent > information here [1] > and a small clarification here [2]. > > Cheers > -K- > > [1] https://httpd.apache.org/security/vulnerabilities_24.html > [2] https://bz.apache.org/bugzilla/show_bug.cgi?id=60783 I would like to learn if and when RedHat will release an updated httpd package to address this CVE for RHEL6 and 7. There's a comment from a month ago that says the backporting is already completed. How long should it take to get from there to a package released to customers? See comment 7: Luboš Uhliarik 2017-01-31 08:40:58 EST: Dear Brian, please check bugs for RHEL-7, RHEL-7 Z-stream and RHEL-6. They are all in modified state. I've finished backporting and QE should now take care of it. This is just tracking bug. This is a high-scoring security problem on everyone's PCI scanners -- it's scoring 4.4, so your customers have to address it within 30 days of detection, and neither of your current RHEL platforms have a fix yet. This is a pretty bad situation to leave customers in. I had found several weeks ago in one of the related bugs (that I can no longer access) that the patched package Lubos mentioned had caused issues with yum and/or satellite server, so there is probably still work going on to fix this, but no status update here is bad. Hello Dan, Trever, Tracking bugs for the specific products, i.e. RHEL-6 and RHEL-7 in this case, are almost always kept private. As you've already found out, there were some problems with the patch which caused the delay, but we're working on fixing this issue. If you have some questions, please email secalert. Thank you! Hello, Adam: This bug has many customer cases connected. Is there an ETA we can share with our clients? Thank you! This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:0906 https://access.redhat.com/errata/RHSA-2017:0906 (In reply to errata-xmlrpc from comment #18) > This issue has been addressed in the following products: > > Red Hat Enterprise Linux 7 > > Via RHSA-2017:0906 https://access.redhat.com/errata/RHSA-2017:0906 Is it still going to be addressed in RHEL 6? This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS Via RHSA-2017:1161 https://access.redhat.com/errata/RHSA-2017:1161 (In reply to errata-xmlrpc from comment #20) > This issue has been addressed in the following products: > > Red Hat Software Collections for Red Hat Enterprise Linux 6 > Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS > Red Hat Software Collections for Red Hat Enterprise Linux 7 > Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS > > Via RHSA-2017:1161 https://access.redhat.com/errata/RHSA-2017:1161 Does that mean that it won't also be addressed in the main (non-SCL)channel for RHEL6? This httpd fix uncovered a bug in the yum-rhn-plugin, which prevents yum from being able to install updates from Red Hat Satellite 5, Red Hat Satellite Proxy 5, or Red Hat Network if httpd fix is applied on the server side. The following knowledge base article provides further information about this problem and provides instructions on how to avoid it. https://access.redhat.com/articles/3013361 This issue has been addressed in the following products: Red Hat JBoss Core Services Via RHSA-2017:1415 https://access.redhat.com/errata/RHSA-2017:1415 This issue has been addressed in the following products: JBoss Core Services on RHEL 6 Via RHSA-2017:1414 https://access.redhat.com/errata/RHSA-2017:1414 This issue has been addressed in the following products: JBoss Core Services on RHEL 7 Via RHSA-2017:1413 https://access.redhat.com/errata/RHSA-2017:1413 This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2017:1721 https://access.redhat.com/errata/RHSA-2017:1721 |