Red Hat released JBoss Enterprise Web Server 2.1.1 for RHEL 6 and RHEL 7 to address four Important vulnerabilities in Apache HTTP Server, OpenSSL, and mod_cluster. The update fixes CVE-2016-5387 (HTTPoxy), where an attacker-supplied Proxy HTTP header can set the HTTP_PROXY environment variable for CGI scripts and redirect their outbound HTTP requests through an attacker-controlled proxy.
The advisories also remediate OpenSSL integer-overflow buffer-overflow flaws CVE-2016-2105 and CVE-2016-2106, which could cause denial of service or potentially code execution, and CVE-2016-3110, a crafted mod_cluster MCMP-message flaw that can crash Apache httpd. Red Hat advised affected organizations to back up installations, apply the update, restart JBoss and OpenSSL-linked services, or reboot affected hosts.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2016:1851 to fix CVE-2016-5387 in the jbcs-httpd24-httpd package for JBoss Core Services on RHEL 6 and RHEL 7.
Red Hat issued RHSA-2016:1648, upgrading JBoss Web Server 2.1.0 to 2.1.1 on RHEL 7. The advisory remediated HTTPoxy and the OpenSSL and mod_cluster vulnerabilities CVE-2016-2105, CVE-2016-2106, and CVE-2016-3110.
Red Hat issued RHSA-2016:1649, upgrading JBoss Web Server 2.1.0 to 2.1.1 on RHEL 6. The update fixed HTTPoxy along with CVE-2016-2105, CVE-2016-2106, and CVE-2016-3110.
The Apache Software Foundation published an HTTPoxy advisory recommending that Apache HTTP Server deployments strip inbound Proxy headers or apply a source patch for CVE-2016-5387. It also documented mitigations and a planned patch for Apache Tomcat's optional CGI Servlet, tracked as CVE-2016-5388.
Red Hat issued RHSA-2016:1421 for RHEL 5 and RHEL 6 and RHSA-2016:1422 for RHEL 7, updating the httpd package to remediate CVE-2016-5387 (HTTPoxy).
Red Hat resolved Bugzilla 1338646 as ERRATA through RHSA-2016:1650, updating JBoss Enterprise Web Server 2 from version 2.1.0 to 2.1.1 to address CVE-2016-3110. The medium-severity mod_cluster flaw could be exploited remotely to cause the Apache HTTP Server to segfault.
Red Hat closed Bugzilla 1337155 as ERRATA and directed JBoss Enterprise Web Server 2.1.0 users to RHSA-2016:1650 for updated packages addressing the medium-severity OpenSSL EVP_EncryptUpdate overflow, CVE-2016-2106, in JBEWS 2.1.1.
Red Hat closed Bugzilla issue 1358118 as ERRATA after RHSA-2016:1650 supplied updated files fixing CVE-2016-5387 in JBoss Enterprise Web Server 2.1.1. The issue also noted that an affected-looking libhttpd.dll in EAP 5.2 was a packaging error and should not be used.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcerhn.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.