Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1326320 - (CVE-2016-3110) CVE-2016-3110 mod_cluster: remotely Segfault Apache http server
CVE-2016-3110 mod_cluster: remotely Segfault Apache http server
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20160822,repor...
: Security
Depends On: 1374210 1374211 1326325 1326327 1326328 1338646
Blocks: 1326299
  Show dependency treegraph
 
Reported: 2016-04-12 08:11 EDT by Timothy Walsh
Modified: 2016-11-08 11:22 EST (History)
28 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was discovered that it is possible to remotely Segfault Apache http server with a specially crafted string sent to the mod_cluster via service messages (MCMP).
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2016:1648 normal SHIPPED_LIVE Important: Red Hat JBoss Web Server 2.1.1 security update on RHEL 7 2016-08-22 18:07:56 EDT
Red Hat Product Errata RHSA-2016:1649 normal SHIPPED_LIVE Important: Red Hat JBoss Web Server 2.1.1 security update on RHEL 6 2016-08-22 18:07:30 EDT
Red Hat Product Errata RHSA-2016:1650 normal SHIPPED_LIVE Important: Red Hat JBoss Web Server 2.1.1 security update 2016-08-22 18:07:23 EDT
Red Hat Product Errata RHSA-2016:2054 normal SHIPPED_LIVE Moderate: Red Hat JBoss Enterprise Application Platform 6.4.10 natives update on RHEL 7 2017-03-23 18:23:49 EDT
Red Hat Product Errata RHSA-2016:2055 normal SHIPPED_LIVE Moderate: Red Hat JBoss Enterprise Application Platform 6.4.10 natives update on RHEL 6 2017-02-21 00:08:14 EST
Red Hat Product Errata RHSA-2016:2056 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 6.4.10 update 2016-10-12 16:57:34 EDT

  None (edit)
Description Timothy Walsh 2016-04-12 08:11:43 EDT
It is possible to remotely Segfault
Apache http server with a specially crafted string
sent to the mod_cluster via service messages (MCMP).

Only the VirtualHost explicitly enabled by an administrator
to receive service messages from worker nodes (Tomcat or EAP workers).
Unless the administrator made a grave mistake in opening an
unsecured mod_cluster management VirtualHost to
the Internet without any authentication, it is impossible
to exploit this bug from an untrusted client.

Special set of mod_cluster management protocol HTTP method
requests. One could pass a certain number of = symbols
in sequence after a legitimate element and cause segfault.
Comment 1 Timothy Walsh 2016-04-12 08:11:54 EDT
Acknowledgments:

Name: Michal Karm Babacek
Comment 5 errata-xmlrpc 2016-08-22 14:09:24 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Web Server 2.1.1

Via RHSA-2016:1650 https://rhn.redhat.com/errata/RHSA-2016-1650.html
Comment 6 errata-xmlrpc 2016-08-22 14:11:14 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Web Server 2 for RHEL 6

Via RHSA-2016:1649 https://rhn.redhat.com/errata/RHSA-2016-1649.html
Comment 7 errata-xmlrpc 2016-08-22 14:12:07 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Web Server 2 for RHEL 7

Via RHSA-2016:1648 https://rhn.redhat.com/errata/RHSA-2016-1648.html
Comment 8 Timothy Walsh 2016-09-08 05:07:27 EDT
Created mod_cluster tracking bugs for this issue:

Affects: fedora-all [bug 1374210]
Affects: epel-6 [bug 1374211]
Comment 9 errata-xmlrpc 2016-10-12 12:59:42 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4.10

Via RHSA-2016:2056 https://rhn.redhat.com/errata/RHSA-2016-2056.html
Comment 10 errata-xmlrpc 2016-10-12 13:08:35 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7

Via RHSA-2016:2054 https://rhn.redhat.com/errata/RHSA-2016-2054.html
Comment 11 errata-xmlrpc 2016-10-12 13:19:19 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6

Via RHSA-2016:2055 https://rhn.redhat.com/errata/RHSA-2016-2055.html

Note You need to log in before you can comment on or make changes to this bug.