Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1338646 - CVE-2016-3110 mod_cluster: remotely Segfault Apache http server
CVE-2016-3110 mod_cluster: remotely Segfault Apache http server
Status: CLOSED ERRATA
Product: JBoss Enterprise Web Server 2
Classification: JBoss
Component: mod_cluster (Show other bugs)
2.1.0
All Linux
medium Severity medium
: DR02
: 2.1.1
Assigned To: Jean-frederic Clere
Michal Karm Babacek
: Security, SecurityTracking
Depends On: 1326328
Blocks: CVE-2016-3110
  Show dependency treegraph
 
Reported: 2016-05-23 04:06 EDT by Michal Karm Babacek
Modified: 2016-09-08 05:25 EDT (History)
20 users (show)

See Also:
Fixed In Version:
Doc Type: Release Note
Doc Text:
Story Points: ---
Clone Of: 1326328
Environment:
Last Closed: 2016-08-22 14:10:17 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
JBoss Issue Tracker MODCLUSTER-488 Blocker Resolved EMBARGOED CVE-2016-3110 mod_cluster segfaults if jvmRoute contains symbols = (number varies) 2017-11-27 17:06 EST
Red Hat Product Errata RHSA-2016:1648 normal SHIPPED_LIVE Important: Red Hat JBoss Web Server 2.1.1 security update on RHEL 7 2016-08-22 18:07:56 EDT
Red Hat Product Errata RHSA-2016:1649 normal SHIPPED_LIVE Important: Red Hat JBoss Web Server 2.1.1 security update on RHEL 6 2016-08-22 18:07:30 EDT
Red Hat Product Errata RHSA-2016:1650 normal SHIPPED_LIVE Important: Red Hat JBoss Web Server 2.1.1 security update 2016-08-22 18:07:23 EDT

  None (edit)
Description Michal Karm Babacek 2016-05-23 04:06:25 EDT
+++ This bug was initially created as a clone of Bug #1326328 +++

eap-6.4.z tracking bug for mod_cluster: see blocks bug list for full details of the security issue(s).

This bug is never intended to be made public, please put any public notes
in the blocked bugs.

NOTE THIS ISSUE IS CURRENTLY EMBARGOED, DO NOT MAKE PUBLIC COMMITS OR COMMENTS ABOUT THIS ISSUE.

NOTICE: THIS BUG HAS THE DEFAULT OWNER (jboss-set@redhat.com) OVERRIDDEN BECAUSE IT WAS A MAILING LIST!  PLEASE CONTACT secalert@redhat.com IF THIS CONFUSES YOU.

[bug automatically created by: add-tracking-bugs]

--- Additional comment from JBoss JIRA Server on 2016-05-20 05:42:27 EDT ---

Radoslav Husar <rhusar@redhat.com> updated the status of jira MODCLUSTER-488 to Reopened
Comment 2 errata-xmlrpc 2016-08-22 14:10:17 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2016-1650.html

Note You need to log in before you can comment on or make changes to this bug.