Red Hat released security updates for affected JBoss Enterprise Application Platform 6.4 and JBoss Core Services Apache HTTP Server 2.4.23 deployments, addressing multiple OpenSSL and Apache HTTP Server vulnerabilities. The OpenSSL fixes include CVE-2016-8610 (“SSL-Death-Alert”), CVE-2016-6304, CVE-2016-2178, and CVE-2016-2177, which can enable remote memory or CPU exhaustion, crashes caused by integer-overflow conditions, and potential local recovery of DSA private-key material.
The Apache HTTP Server service-pack update also resolves vulnerabilities associated with denial of service, padding-oracle attacks, request smuggling and cache poisoning, and local private-key recovery. Affected organizations should apply the relevant Red Hat updates, then restart JBoss server processes and other services linked to OpenSSL, or reboot systems to ensure patched libraries are loaded.

See real exploitation activity before you spend the cycle.
38 events from the most recent confirmed update back to the earliest known activity.
Red Hat remediated CVE-2016-4975 in JBoss Core Services components on RHEL 6 through RHSA-2018:2186. The mod_userdir flaw allowed CRLF injection into HTTP headers, enabling HTTP response splitting and potential access to secure data.
Red Hat issued RHSA-2018:2186 to remediate the OpenSSL TLS session-ticket parsing flaw CVE-2016-6302 in JBoss Core Services components on RHEL 6. The integer-underflow flaw could allow an unauthenticated remote attacker to crash a TLS server using SHA-512 HMAC session tickets.
Red Hat issued Moderate-severity advisory RHSA-2018:2187 for JBoss Core Services Apache HTTP Server 2.4.29 on x86_64, replacing the 2.4.23 release and upgrading bundled OpenSSL to 1.0.2n. The update remediated nine OpenSSL vulnerabilities, including CVE-2016-2182, CVE-2016-6302, CVE-2016-6306, CVE-2016-7055, and CVE-2017-3731 through CVE-2017-3738.
Red Hat issued Moderate-severity advisory RHSA-2018:2185 for JBoss Core Services Apache HTTP Server 2.4.29 on RHEL 7, replacing the 2.4.23 packages and upgrading bundled OpenSSL to 1.0.2n. The update fixed multiple OpenSSL flaws, including CVE-2016-2182, CVE-2016-6302, CVE-2016-6306, CVE-2016-7055, and CVE-2017-3731 through CVE-2017-3738.
Red Hat issued Important advisory RHSA-2017:3475 for JBoss Core Services Apache HTTP Server 2.4.23 Service Pack 3, superseding the prior 2.4.23 release. The update addressed CVE-2017-12613, CVE-2017-3167, CVE-2017-3169, CVE-2017-7679, and the Optionsbleed use-after-free flaw CVE-2017-9798.
Red Hat issued Important advisory RHSA-2017:3476 for JBoss Core Services Apache HTTP Server 2.4.23 Service Pack 3 on RHEL 7, superseding Service Pack 2. The update remediated five Apache HTTP Server and APR flaws, including authentication bypass CVE-2017-3167, APR data-disclosure or denial-of-service CVE-2017-12613, and the .htaccess use-after-free flaw CVE-2017-9798.
Red Hat issued Important advisory RHSA-2017:2709 for JBoss Core Services 1 on RHEL 7, updating Apache HTTP Server from 2.4.23 Service Pack 1 to Service Pack 2. The update remediated the mod_auth_digest information-disclosure or child-process-crash flaw CVE-2017-9788, the authentication-API access-control flaw CVE-2015-3185, and the SWEET32 TLS issue CVE-2016-2183.
Red Hat issued Important advisory RHSA-2017:1801 for JBoss Web Server 3.1 on RHEL 6 and RHEL 7, providing Service Pack 1 and updated Log4j, Tomcat Native, Tomcat 7, and Tomcat 8 packages. The update remediated CVE-2017-5645, which could enable remote code execution through unsafe Log4j socket-server deserialization, along with multiple Apache Tomcat flaws.
Red Hat issued Important advisory RHSA-2017:1659 for JBoss EAP 6.4.16 natives on RHEL 6, delivering a new OpenSSL release. The update remediated CVE-2016-6304, CVE-2016-2178, CVE-2016-8610, and CVE-2016-2177; administrators were advised to back up installations and upgrade affected packages.
Red Hat issued Important advisory RHSA-2017:1658, updating native OpenSSL packages for JBoss Enterprise Application Platform 6.4 on RHEL 6 and 7. The update remediated CVE-2016-6304, CVE-2016-2178, CVE-2016-8610, and CVE-2016-2177; Red Hat instructed users to restart affected services or reboot after installation.
Andrej Nemec documented CVE-2017-3167, in which third-party Apache HTTP Server modules invoking ap_get_basic_auth_pw() outside the authentication phase could bypass authentication requirements. Apache fixed the issue in its 2.4 and 2.2 branches, and Red Hat later issued errata across RHEL, Software Collections, and JBoss Core Services.
Andrej Nemec reported CVE-2017-3169, in which mod_ssl could dereference a NULL pointer and crash Apache HTTP Server when a third-party module invoked ap_hook_process_connection() during an HTTP request sent to an HTTPS port. Apache committed upstream fixes for both the 2.4 and 2.2 branches.
Red Hat published CVE-2017-7679, a Moderate-severity buffer over-read vulnerability in Apache HTTP Server's mod_mime module. A user able to modify HTTPD MIME configuration could trigger crashes of HTTPD child processes; Red Hat later issued fixes for affected RHEL and JBoss Core Services packages.
Red Hat issued Important advisory RHSA-2017:1415 for JBoss Core Services Apache HTTP Server 2.4.23 Service Pack 1, replacing the prior release. The update fixed seven Apache HTTP Server and OpenSSL flaws, including CVE-2016-6304, CVE-2016-7056, and CVE-2016-8610.
Red Hat issued RHSA-2017:1413 for RHEL 7 and RHSA-2017:1414 for RHEL 6, updating JBoss Core Services Apache HTTP Server packages to address CVE-2016-8740. The flaw could let an unauthenticated remote attacker crash HTTP/2-enabled httpd servers through oversized request headers.
Red Hat issued RHSA-2017:1161 to address CVE-2016-8743 in Red Hat Software Collections on RHEL 6, RHEL 6.7 EUS, RHEL 7, and RHEL 7.3 EUS. The flaw's request-parsing behavior could enable request smuggling or response desynchronization in proxy or back-end deployments.
Red Hat issued RHSA-2017:0906 to update the RHEL 7 httpd package for CVE-2016-8743. The HTTP request-parsing flaw could permit response injection and proxy-cache poisoning when httpd was deployed with a proxy or backend that interpreted malformed headers differently.
Red Hat issued RHSA-2017:0906 to update the RHEL 7 httpd package and remediate CVE-2016-2161. The mod_auth_digest memory-allocation handling flaw could allow an unauthenticated remote attacker to repeatedly crash httpd child processes when HTTP Digest authentication was enabled.
Red Hat issued Important advisory RHSA-2017:0194 for JBoss Core Services 1 on RHEL 7, replacing Apache Server 2.4.6 with version 2.4.23 packages. The update remediated six OpenSSL, mod_jk, and mod_cluster flaws, including the potentially code-execution-capable OpenSSL ASN.1 flaw CVE-2016-2108.
Red Hat issued Important advisory RHSA-2017:0193 for JBoss Core Services Pack Apache Server 2.4.23 on RHEL 6, replacing version 2.4.6. The update remediated six flaws in OpenSSL, mod_jk, and mod_cluster, including the potentially code-execution-capable OpenSSL ASN.1 flaw CVE-2016-2108 and denial-of-service or buffer-overflow flaws CVE-2016-6808, CVE-2016-4459, and CVE-2016-8612.
Adam Mariš reported CVE-2016-2161 to Red Hat. The mod_auth_digest flaw could crash Apache HTTP Server instances with malicious input and cause subsequent valid requests to continue triggering crashes.
Red Hat reported and tracked CVE-2016-0736, a medium-severity padding-oracle flaw in Apache HTTP Server's mod_session_crypto module. Unauthenticated session data or cookies could let an attacker decipher protected session data or tamper with it; upstream fixed the issue in httpd 2.4.25.
Red Hat published its CVE record for CVE-2016-8612, classifying the mod_cluster protocol-parsing issue as a low-severity improper-input-validation vulnerability. Crafted protocol values from an adjacent network could crash the serving httpd process and cause denial of service.
Red Hat published CVE-2016-8610, a moderate-severity TLS/SSL denial-of-service issue in which large volumes of SSL ALERT messages during connection handshakes can exhaust CPU and block other client connections. Red Hat identified Nginx as affected, while Apache HTTP Server was not affected.
Andrej Nemec reported CVE-2016-8612, a protocol-parsing flaw in JBoss Core Services mod_cluster modules. Crafted mod_cluster service messages could cause the serving httpd process to segfault and deny service, although properly restricted internal worker-node networks limited exposure.
Shi Lei of Qihoo 360's Gear Team reported CVE-2016-6304 to OpenSSL. A malicious TLS client could repeatedly renegotiate with oversized OCSP status_request extensions, causing unbounded server memory growth and denial of service; Matt Caswell developed the fix.
Timothy Walsh reported CVE-2016-4459, a buffer overflow in mod_cluster's mod_manager component. A JVMRoute value longer than 80 characters could reach an unsafe strcpy operation, crash Apache HTTPD 2.2, and cause denial of service.
César Pereida, Billy Brumley, and Yuval Yarom reported CVE-2016-2178 to OpenSSL. The low-severity flaw failed to preserve a constant-time flag in some DSA signing operations, enabling a demonstrated cache-timing attack that could recover a victim's private DSA key.
Guido Vranken reported CVE-2016-2177 to OpenSSL. The low-severity flaw involved undefined pointer arithmetic in bounds checks that could allow an oversized externally supplied length to bypass buffer validation; OpenSSL later fixed it in versions 1.0.1u and 1.0.2i.
David Benjamin of Google reported the combined security impact of two ASN.1 parsing and encoding defects in OpenSSL. CVE-2016-2108 could cause a buffer underflow and out-of-bounds write when applications deserialize attacker-controlled ASN.1 ANY structures and later reserialize them, potentially affecting X.509 certificate parsing and re-encoding applications.
Red Hat documented CVE-2017-9798 (Optionsbleed), an Apache HTTP Server use-after-free that can disclose process memory through crafted HTTP OPTIONS requests when untrusted users can use invalid methods in .htaccess Limit or LimitExcept directives. Red Hat identified affected RHEL, Software Collections, and JBoss packages under the vulnerable configuration and released backported fixes across those product lines; restricting Limit directives in .htaccess mitigates the issue.
Red Hat documented CVE-2016-7055 as a low-severity carry-propagation flaw in OpenSSL's Broadwell-specific Montgomery multiplication implementation. Crafted inputs larger than and divisible by 256 bits could cause erroneous public-key-operation results or transient authentication and key-negotiation failures; a Brainpool P-512 ECDH attack was considered possible only under unlikely shared-key and multi-client conditions.
Red Hat remediated the mod_mime buffer over-read flaw CVE-2017-7679 through advisories for RHEL 6 and 7, Red Hat Software Collections, RHEL extended-support releases, and JBoss Core Services. Apache had fixed the issue in both its 2.4 and 2.2 branches; JBoss EAP 5 was outside security-support scope.
Red Hat addressed the APR out-of-bounds access flaw CVE-2017-12613 across RHEL, JBoss Core Services, JBoss Web Server, Software Collections, and extended-support products through multiple advisories. The flaw affects APR 1.6.2 and earlier when invalid month values reach apr_exp_time* or apr_os_exp_time* conversion functions, potentially disclosing memory or causing denial of service.
Red Hat advisory RHSA-2016:2957 addressed CVE-2016-6808 for JBoss Core Services on RHEL 7. The IIS/ISAPI-specific mod_jk flaw could overflow a mapping-rule buffer because virtual-host name length was omitted when concatenating the virtual-host name and URI; Apache fixed it in Tomcat JK Connector 1.2.42.
Red Hat released an Important-security-impact update to JBoss Core Services httpd 2.4.23 for Solaris and Microsoft Windows, replacing version 2.4.6. The update remediated flaws across OpenSSL, libxml2, curl, httpd, mod_cluster, mod_jk, and expat, including the mod_jk buffer overflow CVE-2016-6808.
Red Hat addressed the OpenSSL TLS WARNING ALERT denial-of-service flaw CVE-2016-8610 in RHEL 6 and RHEL 7 through RHSA-2017:0286, with an additional RHEL 6 update issued as RHSA-2017:0574. The flaw could let attackers consume CPU by repeatedly sending plaintext warning alerts during TLS handshakes.
OpenSSL released fixes for CVE-2016-8610, the SSL Death Alert denial-of-service flaw, in versions 1.0.2j and 1.1.0b. The flaw allowed repeated undefined plaintext TLS warning alerts to drive vulnerable OpenSSL-backed services to excessive CPU consumption.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
openssl.org
Open sourcecve.org
Open sourcecve.org
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcesecurity.360.cn
Open sourcebugzilla.redhat.com
Open sourcegit.openssl.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.