CVE-2017-2666
published 2018-07-27CVE-2017-2666: It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a…
PriorityP433medium6.5CVSS 3.0
AVNACLPRNUINSUCLILAN
EPSS
2.71%
84.3th percentile
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | undertow | < undertow 2.2.0-1 (forky) | undertow 2.2.0-1 (forky) |
| debian | undertow | < undertow 1.4.18-1 (forky) | undertow 1.4.18-1 (forky) |
| debian | undertow | < undertow 1.4.23-1 (forky) | undertow 1.4.23-1 (forky) |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | undertow | < 2.0.34 | 2.0.34 |
| redhat | undertow | < 2.2.0 | 2.2.0 |
| redhat | undertow | — | — |
| redhat | undertow | >= 0 < 2.2.0-1 | 2.2.0-1 |
| redhat | undertow | >= 0 < 1.4.23-1 | 1.4.23-1 |
| redhat | undertow | >= 0 < 1.4.18-1 | 1.4.18-1 |
| redhat | undertow | >= 1.3.0 < 1.3.31 | 1.3.31 |
| redhat | undertow | >= 1.4.0 < 1.4.17 | 1.4.17 |
| redhat | undertow | >= 2.1.0 < 2.1.6 | 2.1.6 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Undertow vulnerable to Request Smuggling
ghsa·2022-05-13·CVSS 6.5
CVE-2017-7559 [MEDIUM] CWE-444 Undertow vulnerable to Request Smuggling
Undertow vulnerable to Request Smuggling
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
OSV
Undertow vulnerable to Request Smuggling
osv·2022-05-13·CVSS 6.5
CVE-2017-7559 [MEDIUM] Undertow vulnerable to Request Smuggling
Undertow vulnerable to Request Smuggling
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
OSV
HTTP request smuggling in Undertow
osv·2021-06-16·CVSS 6.5
CVE-2021-20220 [MEDIUM] HTTP request smuggling in Undertow
HTTP request smuggling in Undertow
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
GHSA
HTTP request smuggling in Undertow
ghsa·2021-06-16·CVSS 6.5
CVE-2021-20220 [MEDIUM] CWE-444 HTTP request smuggling in Undertow
HTTP request smuggling in Undertow
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
OSV
HTTP Request Smuggling in Undertow
osv·2021-04-30·CVSS 6.5
CVE-2020-10687 [MEDIUM] HTTP Request Smuggling in Undertow
HTTP Request Smuggling in Undertow
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
GHSA
HTTP Request Smuggling in Undertow
ghsa·2021-04-30·CVSS 6.5
CVE-2020-10687 [MEDIUM] CWE-444 HTTP Request Smuggling in Undertow
HTTP Request Smuggling in Undertow
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
OSV
CVE-2021-20220: A flaw was found in Undertow
osv·2021-02-23·CVSS 6.5
CVE-2021-20220 [MEDIUM] CVE-2021-20220: A flaw was found in Undertow
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
OSV
CVE-2020-10687: A flaw was discovered in all versions of Undertow before Undertow 2
osv·2020-09-23·CVSS 6.5
CVE-2020-10687 [MEDIUM] CVE-2020-10687: A flaw was discovered in all versions of Undertow before Undertow 2
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
OSV
Undertow-core vulnerable to HTTP Request Smuggling
osv·2018-10-19
CVE-2017-2666 [MEDIUM] Undertow-core vulnerable to HTTP Request Smuggling
Undertow-core vulnerable to HTTP Request Smuggling
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
GHSA
Undertow-core vulnerable to HTTP Request Smuggling
ghsa·2018-10-19
CVE-2017-2666 [MEDIUM] CWE-444 Undertow-core vulnerable to HTTP Request Smuggling
Undertow-core vulnerable to HTTP Request Smuggling
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
OSV
CVE-2017-2666: It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters
osv·2018-07-27·CVSS 6.5
CVE-2017-2666 [MEDIUM] CVE-2017-2666: It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
OSV
CVE-2017-7559: In Undertow 2
osv·2018-01-10·CVSS 6.5
CVE-2017-7559 [MEDIUM] CVE-2017-7559: In Undertow 2
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
Red Hat
undertow: Possible regression in fix for CVE-2020-10687
vendor_redhat·2021-02-04·CVSS 6.5
CVE-2021-20220 [MEDIUM] CWE-444 undertow: Possible regression in fix for CVE-2020-10687
undertow: Possible regression in fix for CVE-2020-10687
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perfo
Debian
CVE-2021-20220: undertow - A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was fou...
vendor_debian·2021·CVSS 6.5
CVE-2021-20220 [MEDIUM] CVE-2021-20220: undertow - A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was fou...
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
Scope: local
forky: resolved (fixed in 2.2.0-1)
sid: resolved (fixed in 2.2.0-1)
Red Hat
Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests
vendor_redhat·2020-04-15·CVSS 6.5
CVE-2020-10687 [MEDIUM] CWE-444 Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests
Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
A flaw was discovered in Undertow where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
P
Debian
CVE-2020-10687: undertow - A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, w...
vendor_debian·2020·CVSS 6.5
CVE-2020-10687 [MEDIUM] CVE-2020-10687: undertow - A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, w...
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
Scope: local
forky: resolved (fixed in 2.2.0-1)
sid: resolved (fixed in 2.2.0-1)
Red Hat
undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)
vendor_redhat·2017-12-13·CVSS 6.5
CVE-2017-7559 [MEDIUM] CWE-444 undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)
undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
It was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This
Red Hat
undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests
vendor_redhat·2017-06-07·CVSS 6.5
CVE-2017-2666 [MEDIUM] CWE-444 undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests
undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
It was discovered that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the
Debian
CVE-2017-2666: undertow - It was discovered in Undertow that the code that parsed the HTTP request line pe...
vendor_debian·2017·CVSS 6.5
CVE-2017-2666 [MEDIUM] CVE-2017-2666: undertow - It was discovered in Undertow that the code that parsed the HTTP request line pe...
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
Scope: local
forky: resolved (fixed in 1.4.18-1)
sid: resolved (fixed in 1.4.18-1)
Debian
CVE-2017-7559: undertow - In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before...
vendor_debian·2017·CVSS 6.5
CVE-2017-7559 [MEDIUM] CVE-2017-7559: undertow - In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before...
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
Scope: local
forky: resolved (fixed in 1.4.23-1)
sid: resolved (fixed in 1.4.23-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10687 Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests
bugzilla·2019-12-19·CVSS 6.5
CVE-2020-10687 [MEDIUM] CVE-2020-10687 Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests
CVE-2020-10687 Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests
A flaw was found in Undertow where HTTP request smuggling related to CVE-2017-2666 might still be possible against HTTP/2.
Discussion:
Acknowledgments:
Name: Aaron Ogburn (Red Hat)
---
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss Fuse 6
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2020:3464 https://access.redhat.com/errata/RHSA-2020:3464
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.3 for RH
Bugzilla
CVE-2017-2666 undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests [fedora-all]
bugzilla·2017-08-15·CVSS 6.5
CVE-2017-2666 [MEDIUM] CVE-2017-2666 undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests [fedora-all]
CVE-2017-2666 undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NO
Bugzilla
CVE-2017-7559 undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)
bugzilla·2017-08-15·CVSS 6.5
CVE-2017-7559 [MEDIUM] CVE-2017-7559 undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)
CVE-2017-7559 undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)
It was found that original patch for CVE-2017-2666 issue in undertow was incomplete and invalid characters are still allowed in the query string and path parameters.
Discussion:
Acknowledgments:
Name: Stuart Douglas (Red Hat)
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2017:3456 https://access.redhat.com/errata/RHSA-2017:3456
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
Via RHSA-2017:3454 https://access.redhat.com/errata/RHSA-2017:3454
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Pla
Bugzilla
CVE-2017-2670 undertow: IO thread DoS via unclean Websocket closing
bugzilla·2017-04-04·CVSS 6.5
CVE-2017-2670 [MEDIUM] CVE-2017-2670 undertow: IO thread DoS via unclean Websocket closing
CVE-2017-2670 undertow: IO thread DoS via unclean Websocket closing
It was found that with non-clean TCP close, Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
Vulnerable code:
https://github.com/undertow-io/undertow/blob/1.4.12.Final/core/src/main/java/io/undertow/server/protocol/framed/AbstractFramedStreamSourceChannel.java#L288
Discussion:
*** Bug 1438764 has been marked as a duplicate of this bug. ***
---
Acknowledgments:
Name: Gregory Ramsperger, Ryan Moak
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.0.6
Via RHSA-2017:1409 https://rhn.redhat.com/errata/RHSA-2017-1409.html
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application P
Bugzilla
CVE-2017-2666 undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests
bugzilla·2017-03-27·CVSS 6.5
CVE-2017-2666 [MEDIUM] CVE-2017-2666 undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests
CVE-2017-2666 undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests
It was found that code that parsed the HTTP request line in undertow permitted invalid characters which results into HTTP request smuggling vulnerability.
Discussion:
Acknowledgments:
Name: Radim Hatlapatka (Red Hat)
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.0.6
Via RHSA-2017:1409 https://rhn.redhat.com/errata/RHSA-2017-1409.html
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
Via RHSA-2017:1411 https://access.redhat.com/errata/RHSA-2017:1411
---
This issue has been addressed in the following products:
Red Hat JBoss Enterpr
CAPEC
HTTP Response Smuggling
mitre_capec
[HIGH] HTTP Response Smuggling
CAPEC-273: HTTP Response Smuggling
An adversary manipulates and injects malicious content in the form of secret unauthorized HTTP responses, into a single HTTP response from a vulnerable or compromised back-end HTTP agent (e.g., server). See CanPrecede relationships for possible consequences.
Alternate Terms: HTTP Desync
Execution Flow:
Step 1 [Explore]: [Survey network to identify target] The adversary performs network reconnaissance by monitoring relevant traffic to identify the network path and parsing of the HTTP messages with the goal of identifying potential targets.
Technique: Scan networks to fingerprint HTTP infrastructure and monitor HTTP traffic to identify HTTP network path with a tool such as a Network Protocol Analyzer.
Step 1 [Experiment]: [Identify vulnerabilities in tar
http://rhn.redhat.com/errata/RHSA-2017-1409.htmlhttp://www.securityfocus.com/bid/98966https://access.redhat.com/errata/RHSA-2017:1410https://access.redhat.com/errata/RHSA-2017:1411https://access.redhat.com/errata/RHSA-2017:1412https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2666https://www.debian.org/security/2017/dsa-3906http://rhn.redhat.com/errata/RHSA-2017-1409.htmlhttp://www.securityfocus.com/bid/98966https://access.redhat.com/errata/RHSA-2017:1410https://access.redhat.com/errata/RHSA-2017:1411https://access.redhat.com/errata/RHSA-2017:1412https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2666https://www.debian.org/security/2017/dsa-3906
2018-07-27
Published