CVE-2016-3110
published 2016-09-26CVE-2016-3110: mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message…
PriorityP335high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.64%
88.4th percentile
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_web_server | — | — |
| redhat | jboss_enterprise_web_server | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
mod_cluster Denial of Service vulnerability
ghsa·2022-05-14
CVE-2016-3110 [HIGH] CWE-20 mod_cluster Denial of Service vulnerability
mod_cluster Denial of Service vulnerability
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.
OSV
mod_cluster Denial of Service vulnerability
osv·2022-05-14
CVE-2016-3110 [HIGH] mod_cluster Denial of Service vulnerability
mod_cluster Denial of Service vulnerability
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.
Red Hat
mod_cluster: remotely Segfault Apache http server
vendor_redhat·2016-08-22·CVSS 7.5
CVE-2016-3110 [HIGH] mod_cluster: remotely Segfault Apache http server
mod_cluster: remotely Segfault Apache http server
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.
It was discovered that it is possible to remotely Segfault Apache http server with a specially crafted string sent to the mod_cluster via service messages (MCMP).
Package: mod_cluster (Red Hat JBoss Enterprise Web Server 3) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3110 mod_cluster: remotely Segfault Apache http server [epel-6]
bugzilla·2016-09-08·CVSS 7.5
CVE-2016-3110 [HIGH] CVE-2016-3110 mod_cluster: remotely Segfault Apache http server [epel-6]
CVE-2016-3110 mod_cluster: remotely Segfault Apache http server [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Disc
Bugzilla
CVE-2016-3110 mod_cluster: remotely Segfault Apache http server [fedora-all]
bugzilla·2016-09-08·CVSS 7.5
CVE-2016-3110 [HIGH] CVE-2016-3110 mod_cluster: remotely Segfault Apache http server [fedora-all]
CVE-2016-3110 mod_cluster: remotely Segfault Apache http server [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
Bugzilla
CVE-2016-3110 mod_cluster: remotely Segfault Apache http server
bugzilla·2016-05-23·CVSS 7.5
CVE-2016-3110 [HIGH] CVE-2016-3110 mod_cluster: remotely Segfault Apache http server
CVE-2016-3110 mod_cluster: remotely Segfault Apache http server
+++ This bug was initially created as a clone of Bug #1326328 +++
eap-6.4.z tracking bug for mod_cluster: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the blocked bugs.
NOTE THIS ISSUE IS CURRENTLY EMBARGOED, DO NOT MAKE PUBLIC COMMITS OR COMMENTS ABOUT THIS ISSUE.
NOTICE: THIS BUG HAS THE DEFAULT OWNER ([email protected]) OVERRIDDEN BECAUSE IT WAS A MAILING LIST! PLEASE CONTACT [email protected] IF THIS CONFUSES YOU.
[bug automatically created by: add-tracking-bugs]
--- Additional comment from JBoss JIRA Server on 2016-05-20 05:42:27 EDT ---
Radoslav Husar updated the status of jira MODCLUSTER-488 to Reopened
Discussi
Bugzilla
CVE-2016-3110 mod_cluster: remotely Segfault Apache http server
bugzilla·2016-04-12·CVSS 7.5
CVE-2016-3110 [HIGH] CVE-2016-3110 mod_cluster: remotely Segfault Apache http server
CVE-2016-3110 mod_cluster: remotely Segfault Apache http server
It is possible to remotely Segfault
Apache http server with a specially crafted string
sent to the mod_cluster via service messages (MCMP).
Only the VirtualHost explicitly enabled by an administrator
to receive service messages from worker nodes (Tomcat or EAP workers).
Unless the administrator made a grave mistake in opening an
unsecured mod_cluster management VirtualHost to
the Internet without any authentication, it is impossible
to exploit this bug from an untrusted client.
Special set of mod_cluster management protocol HTTP method
requests. One could pass a certain number of = symbols
in sequence after a legitimate element and cause segfault.
Discussion:
Acknowledgments:
Name: Michal Karm Babacek
---
This issue ha
http://rhn.redhat.com/errata/RHSA-2016-1648.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1649.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1650.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2054.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2055.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2056.htmlhttp://www.securityfocus.com/bid/92584https://bugzilla.redhat.com/show_bug.cgi?id=1326320https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6JMA2YLPK6SEUVF5Q3QEANHYEPRZA2RI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CX5QNNIVAUB2VVDV6TR3YMFTL6VRKOBO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HE5YZTBZRXCMQFT5LDLZG2HAYBKMYQLL/http://rhn.redhat.com/errata/RHSA-2016-1648.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1649.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1650.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2054.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2055.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2056.htmlhttp://www.securityfocus.com/bid/92584https://bugzilla.redhat.com/show_bug.cgi?id=1326320https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6JMA2YLPK6SEUVF5Q3QEANHYEPRZA2RI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CX5QNNIVAUB2VVDV6TR3YMFTL6VRKOBO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HE5YZTBZRXCMQFT5LDLZG2HAYBKMYQLL/
2016-09-26
Published