Red Hat released updates for the native components of JBoss Enterprise Application Platform (EAP) 6.4.10 on RHEL 6 and RHEL 7, addressing Apache HTTP Server request-smuggling vulnerability CVE-2015-3183 and mod_cluster denial-of-service flaws including CVE-2016-3110 and CVE-2016-4459. CVE-2016-4459 affects mod_cluster's mod_manager component: an oversized JVMRoute path can overflow a buffer and cause a segmentation fault, crashing the server.
The affected updates include mod_cluster-native, mod_jk, tomcat-native, and related native packages. Organizations running affected EAP 6/6.4 deployments should apply the relevant RHEL 6 or RHEL 7 errata, then restart JBoss and services linked against OpenSSL—or reboot hosts—to activate the fixes; Red Hat also issued corrected JBoss Core Services HTTPD 2.4 packages for RHEL 6 and 7 under RHSA-2017:0193 and RHSA-2017:0194.

See real exploitation activity before you spend the cycle.
15 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2017:2709 for RHEL 7 and RHSA-2017:2710 for RHEL 6, updating JBoss Core Services jbcs-httpd24-httpd and jbcs-httpd24-openssl packages to remediate the CVE-2015-3185 improper-authentication flaw.
Red Hat released RHSA-2017:0193 for RHEL 6 and RHSA-2017:0194 for RHEL 7, updating affected JBoss Core Services HTTPD 2.4 packages. The fixes addressed CVE-2016-4459, in which an overlong JVMRoute path could overflow mod_manager and crash the server.
Red Hat issued Moderate-severity advisory RHSA-2016:2055 for JBoss EAP 6 and 6.4 on RHEL 6. The update fixed CVE-2015-3183 and the mod_cluster flaws CVE-2016-3110 and CVE-2016-4459, and required affected services to be restarted or the system rebooted.
Red Hat issued Moderate-severity advisory RHSA-2016:2054 for JBoss EAP 6 and 6.4 on RHEL 7. The native-package update remediated CVE-2015-3183, CVE-2016-3110, and CVE-2016-4459, including mod_cluster denial-of-service flaws that could crash Apache HTTP Server.
Oracle released its July 2016 Critical Patch Update. The supplied reference metadata does not identify the affected products or vulnerabilities addressed.
Red Hat issued Moderate-severity RHSA-2016:0061 for JBoss Enterprise Web Server 2.1.0 on RHEL 5, 6, and 7. Updated httpd and httpd22 packages remediated CVE-2015-3183 request smuggling and CVE-2013-5704 Trailer-header restriction bypass issues.
Red Hat issued Moderate-severity advisory RHSA-2015:2659 for JBoss Enterprise Web Server 3.0.2 on RHEL 6. The update remediated CVE-2015-3183 request smuggling, CVE-2013-5704 Trailer-header restriction bypass, and the CVE-2014-0230 Tomcat connection-pool exhaustion denial-of-service flaw.
Red Hat issued Moderate-impact advisory RHSA-2015:2660 for JBoss Enterprise Web Server 3.0.2 on RHEL 7. The update remediated CVE-2015-3183 request smuggling, CVE-2013-5704 Trailer-header restriction bypass, and CVE-2014-0230, a Tomcat connection-exhaustion denial-of-service flaw.
Red Hat issued RHSA-2015:1668 for Red Hat Enterprise Linux 6 and RHSA-2015:1667 for Red Hat Enterprise Linux 7, updating httpd to remediate the CVE-2015-3183 chunked-transfer parsing flaw that could permit HTTP request smuggling.
Fedora published httpd-2.4.16-1.fc21 to the Fedora 21 stable repository, incorporating Apache HTTP Server 2.4.16's fix for the CVE-2015-3183 chunked-request parsing flaw that could enable HTTP request smuggling.
Fedora published httpd-2.4.16-1.fc22 to the Fedora 22 stable repository, including Apache HTTP Server's fix for the CVE-2015-3183 chunked-request parsing flaw that could enable HTTP request smuggling.
CVE-2015-3183, involving inconsistent parsing of chunked HTTP transfer encoding by Apache httpd and front-end proxies that could enable HTTP request smuggling, became public.
Apache HTTP Server 2.4.68 remediates multiple vulnerabilities affecting earlier 2.4 releases, including flaws in mod_ldap, mod_proxy_html, mod_xml2enc, mod_ssl, mod_http2, mod_dav_fs, and proxy-related functionality. The fixes include privilege-escalation, denial-of-service, memory-safety, and cross-site-scripting issues affecting versions through 2.4.67.
Red Hat addressed the mod_cluster MCMP denial-of-service flaw CVE-2016-3110 in JBoss Web Server 2.1.1, JBoss Enterprise Web Server 2 for RHEL 6 and RHEL 7, and JBoss EAP 6.4.10 through RHSA-2016:1650, RHSA-2016:1649, RHSA-2016:1648, and RHSA-2016:2056.
Red Hat issued RHSA-2015:1666, updating httpd24-httpd packages for Red Hat Software Collections 2. The Moderate-impact update fixed CVE-2015-3183 request smuggling, CVE-2015-3185 authentication API behavior, and denial-of-service flaws CVE-2015-0228 and CVE-2015-0253.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
27 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourceaccess.redhat.com
Open sourcehttpd.apache.org
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourceoracle.com
Open sourcerhn.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.