CVE-2016-3110

Related Vulnerabilities: CVE-2016-3110  

It was discovered that it is possible to remotely Segfault Apache http server with a specially crafted string sent to the mod_cluster via service messages (MCMP).

It was discovered that it is possible to remotely Segfault Apache http server with a specially crafted string sent to the mod_cluster via service messages (MCMP).

Find out more about CVE-2016-3110 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 4.7
Base Metrics AV:L/AC:M/Au:N/C:N/I:N/A:C
Access Vector Local
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Complete

CVSS v3 metrics

CVSS3 Base Score 5.1
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact High

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Application Platform 6.4 RHSA-2016:2056 2016-10-12
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server RHSA-2016:2055 2016-10-12
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 Server (mod_cluster) RHSA-2016:1649 2016-08-22
Red Hat JBoss Web Server 2.1 RHSA-2016:1650 2016-08-22
Red Hat JBoss Enterprise Web Server 2 for RHEL 7 Server (mod_cluster) RHSA-2016:1648 2016-08-22
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 Server RHSA-2016:2054 2016-10-12

Affected Packages State

Platform Package State
Red Hat Software Collections for Red Hat Enterprise Linux httpd24-mod_cluster-native Will not fix
Red Hat JBoss Web Server 3.0 mod_cluster Will not fix

Acknowledgements

Red Hat would like to thank Michal Karm Babacek for reporting this issue.