VDB
RHSA-2017:2494
RHSA-2017:2494
PUBLISHED
CVSS 7.5 HIGH
A memory leak flaw was found in the way OpenSSL handled TLS status request extension data during session renegotiation. A remote attacker could cause a TLS server using OpenSSL to consume an excessive amount of memory and, possibly, exit unexpectedly after exhausting all available memory, if it enabled OCSP stapling support.
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Web Server 2.1 |
Timeline
- Aug 21, 2017 CVE Published
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- May 14, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
References
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=webserver&downloadType=securityPatches&version=2.1.2 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1377600 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1384743 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1441205 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1459158 issue
- https://nvd.nist.gov/vuln/detail/CVE-2016-8610 advisory
- http://security.360.cn/cve/CVE-2016-8610 advisory
- https://access.redhat.com/security/cve/CVE-2017-5647 advisory
- https://www.cve.org/CVERecord?id=CVE-2017-5647 advisory
- https://www.cve.org/CVERecord?id=CVE-2017-5664 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-5664 advisory
- https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.78 advisory
- https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.15 advisory
- https://access.redhat.com/errata/RHSA-2017:2494 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/articles/3155411 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2017/rhsa-2017_2494.json advisory
- https://access.redhat.com/security/cve/CVE-2016-6304 advisory
- https://www.cve.org/CVERecord?id=CVE-2016-6304 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-6304 advisory
…and 6 more