Security Advisory Moderate: JBoss Enterprise Application Platform 4.2.0CP02 security update

Advisory: RHSA-2008:0151-4
Type: Security Advisory
Severity: Moderate
Issued on: 2008-04-02
Last updated on: 2008-04-02
Affected Products: JBoss Enterprise Application Platform 4.2.0 EL4
OVAL: N/A
CVEs (cve.mitre.org): CVE-2007-4575
CVE-2007-5461
CVE-2007-6306
CVE-2007-6433
CVE-2008-0002

Details

Updated JBoss Enterprise Application Platform (JBEAP) packages that fix
several security issues are now available.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

JBoss Enterprise Application Platform (JBEAP) is a middleware platform for
Java 2 Platform, Enterprise Edition (J2EE) applications.

This release of JBEAP for Red Hat Enterprise Linux 4 contains the JBoss
Application Server and JBoss Seam. This release serves as a replacement to
JBEAP 4.2.0.GA. It fixes several security issues:

The JFreeChart component was vulnerable to multiple cross-site scripting
(XSS) vulnerabilities. An attacker could misuse the image map feature to
inject arbitrary web script, or HTML, via several attributes of the chart
area. (CVE-2007-6306)

A vulnerability caused by exposing static Java methods was located within
the HSQLDB component. This could be utilized by an attacker to execute
arbitrary static Java methods. (CVE-2007-4575)

The setOrder method in the org.jboss.seam.framework.Query class did not
correctly validate user-supplied parameters. This vulnerability allowed
remote attackers to inject, and execute, arbitrary Enterprise JavaBeans
Query Language (EJB QL) commands via the order parameter. (CVE-2007-6433)

These updated packages include bug fixes and enhancements which are not
listed here. For a full list, please refer to the JBEAP 4.2.0CP02 release
notes:
http://redhat.com/docs/manuals/jboss/jboss-eap-4.2.0.cp02/readme.html

Warning: before applying this update, please backup the JBEAP
"server/[configuration]/deploy/" directory, and any other customized
configuration files.

All users of JBEAP on Red Hat Enterprise Linux 4 are advised to upgrade to
these updated packages, which resolve these issues.


Solution

A complete installation guide for this new release is linked to in the
References section below.

Before installing this upgrade, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains
the desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

JBoss Enterprise Application Platform 4.2.0 EL4

SRPMS:
concurrent-1.3.4-7jpp.ep1.6.el4.src.rpm     04b34722d6bbc4ceaae81d754760358c
concurrent-1.3.4-7jpp.ep1.6.el4.src.rpm     04b34722d6bbc4ceaae81d754760358c
glassfish-jaf-1.1.0-0jpp.ep1.10.el4.src.rpm
File outdated by:  RHSA-2008:0833
    a6f215133cd9f3560b174f4a332f2717
glassfish-jaf-1.1.0-0jpp.ep1.10.el4.src.rpm
File outdated by:  RHSA-2008:0833
    a6f215133cd9f3560b174f4a332f2717
glassfish-javamail-1.4.0-0jpp.ep1.8.src.rpm
File outdated by:  RHSA-2008:0833
    64812c9a424af06a4109e29a18cb4ea0
glassfish-javamail-1.4.0-0jpp.ep1.8.src.rpm
File outdated by:  RHSA-2008:0833
    64812c9a424af06a4109e29a18cb4ea0
glassfish-jsf-1.2_04-1.p02.0jpp.ep1.18.src.rpm
File outdated by:  RHSA-2008:0825
    a282f47fcd7e7e285ec39588224ac9b7
glassfish-jsf-1.2_04-1.p02.0jpp.ep1.18.src.rpm
File outdated by:  RHSA-2008:0825
    a282f47fcd7e7e285ec39588224ac9b7
glassfish-jstl-1.2.0-0jpp.ep1.2.src.rpm
File outdated by:  RHSA-2008:0833
    bb28324af22feef313162e7d0abf4eda
glassfish-jstl-1.2.0-0jpp.ep1.2.src.rpm
File outdated by:  RHSA-2008:0833
    bb28324af22feef313162e7d0abf4eda
hibernate3-3.2.4-1.SP1_CP02.0jpp.ep1.1.el4.src.rpm
File outdated by:  RHSA-2008:0833
    d49f89c505c8c72856ec9b933a9be1a5
hibernate3-3.2.4-1.SP1_CP02.0jpp.ep1.1.el4.src.rpm
File outdated by:  RHSA-2008:0833
    d49f89c505c8c72856ec9b933a9be1a5
hibernate3-annotations-3.2.1-1.patch02.1jpp.ep1.2.el4.src.rpm
File outdated by:  RHSA-2008:0833
    4a511bb9b633420f8d21ad1b1881db4b
hibernate3-annotations-3.2.1-1.patch02.1jpp.ep1.2.el4.src.rpm
File outdated by:  RHSA-2008:0833
    4a511bb9b633420f8d21ad1b1881db4b
hibernate3-entitymanager-3.2.1-1jpp.ep1.6.el4.src.rpm
File outdated by:  RHSA-2008:0833
    98693f4d1dd2ee2f44c37c35b7afed47
hibernate3-entitymanager-3.2.1-1jpp.ep1.6.el4.src.rpm
File outdated by:  RHSA-2008:0833
    98693f4d1dd2ee2f44c37c35b7afed47
hsqldb-1.8.0.8-2.patch01.1jpp.ep1.1.src.rpm     dc473a0493469d3f6c05ccbd0b8996a7
hsqldb-1.8.0.8-2.patch01.1jpp.ep1.1.src.rpm     dc473a0493469d3f6c05ccbd0b8996a7
jacorb-2.3.0-1jpp.ep1.4.src.rpm     c7341a22ff98a7d48392a34f9b7778a9
jacorb-2.3.0-1jpp.ep1.4.src.rpm     c7341a22ff98a7d48392a34f9b7778a9
jboss-aop-1.5.5-1.CP01.0jpp.ep1.1.el4.src.rpm
File outdated by:  RHSA-2008:0833
    369c3420a9e3954be92c132373d89de3
jboss-aop-1.5.5-1.CP01.0jpp.ep1.1.el4.src.rpm
File outdated by:  RHSA-2008:0833
    369c3420a9e3954be92c132373d89de3
jboss-cache-1.4.1-4.SP8_CP01.1jpp.ep1.1.el4.src.rpm
File outdated by:  RHSA-2008:0825
    e3011bfb6020fe6bbd24603b2fdd02a9
jboss-cache-1.4.1-4.SP8_CP01.1jpp.ep1.1.el4.src.rpm
File outdated by:  RHSA-2008:0825
    e3011bfb6020fe6bbd24603b2fdd02a9
jboss-common-1.2.1-0jpp.ep1.2.src.rpm     c8b105f404565eabc19bd9e904233781
jboss-common-1.2.1-0jpp.ep1.2.src.rpm     c8b105f404565eabc19bd9e904233781
jboss-remoting-2.2.2-3.SP4.0jpp.ep1.1.src.rpm
File outdated by:  RHSA-2008:0833
    1af2397d82121c3eb438946634289d3b
jboss-remoting-2.2.2-3.SP4.0jpp.ep1.1.src.rpm
File outdated by:  RHSA-2008:0833
    1af2397d82121c3eb438946634289d3b
jboss-seam-1.2.1-1.ep1.3.el4.src.rpm
File outdated by:  RHSA-2008:0833
    28debc376f479119544260cb5935f728
jboss-seam-1.2.1-1.ep1.3.el4.src.rpm
File outdated by:  RHSA-2008:0833
    28debc376f479119544260cb5935f728
jbossas-4.2.0-3.GA_CP02.ep1.3.el4.src.rpm
File outdated by:  RHSA-2008:0833
    dc4378d8cf8e5c2bdba79b91c024a73d
jbossas-4.2.0-3.GA_CP02.ep1.3.el4.src.rpm
File outdated by:  RHSA-2008:0833
    dc4378d8cf8e5c2bdba79b91c024a73d
jbossweb-2.0.0-3.CP05.0jpp.ep1.1.src.rpm
File outdated by:  RHSA-2008:0877
    33e8cab4b089356bdb31433283862609
jbossweb-2.0.0-3.CP05.0jpp.ep1.1.src.rpm
File outdated by:  RHSA-2008:0877
    33e8cab4b089356bdb31433283862609
jbossws-jboss42-1.2.1-0jpp.ep1.2.el4.src.rpm
File outdated by:  RHSA-2008:0825
    842afcb21e2af954dbfaf5f7077169e7
jbossws-jboss42-1.2.1-0jpp.ep1.2.el4.src.rpm
File outdated by:  RHSA-2008:0825
    842afcb21e2af954dbfaf5f7077169e7
jbossws-wsconsume-impl-2.0.0-0jpp.ep1.3.src.rpm     786de0d6d4c5063453063961c5c1c894
jbossws-wsconsume-impl-2.0.0-0jpp.ep1.3.src.rpm     786de0d6d4c5063453063961c5c1c894
jbossxb-1.0.0-2.SP1.0jpp.ep1.2.el4.src.rpm
File outdated by:  RHSA-2008:0833
    17c7751a09ff90df01d94f2ac93e2626
jbossxb-1.0.0-2.SP1.0jpp.ep1.2.el4.src.rpm
File outdated by:  RHSA-2008:0833
    17c7751a09ff90df01d94f2ac93e2626
jcommon-1.0.12-1jpp.ep1.2.el4.src.rpm
File outdated by:  RHSA-2008:0825
    a803cc750f51c7b8eeaf5e504d2c57f0
jcommon-1.0.12-1jpp.ep1.2.el4.src.rpm
File outdated by:  RHSA-2008:0825
    a803cc750f51c7b8eeaf5e504d2c57f0
jfreechart-1.0.9-1jpp.ep1.2.el4.src.rpm
File outdated by:  RHSA-2008:0825
    18138ffe5b828606aab531006c6222f8
jfreechart-1.0.9-1jpp.ep1.2.el4.src.rpm
File outdated by:  RHSA-2008:0825
    18138ffe5b828606aab531006c6222f8
jgroups-2.4.1-1.SP4.0jpp.ep1.2.src.rpm
File outdated by:  RHSA-2008:0825
    8424b72226a9c76225cfb11e786227f2
jgroups-2.4.1-1.SP4.0jpp.ep1.2.src.rpm
File outdated by:  RHSA-2008:0825
    8424b72226a9c76225cfb11e786227f2
rh-eap-docs-4.2.0-3.GA_CP02.ep1.1.el4.src.rpm
File outdated by:  RHSA-2008:0833
    66764f79856f327b1dded1e352968390
rh-eap-docs-4.2.0-3.GA_CP02.ep1.1.el4.src.rpm
File outdated by:  RHSA-2008:0833
    66764f79856f327b1dded1e352968390
wsdl4j-1.6.2-1jpp.ep1.8.src.rpm     c98396c0a230baf727996f71cecb7676
wsdl4j-1.6.2-1jpp.ep1.8.src.rpm     c98396c0a230baf727996f71cecb7676
 
IA-32:
concurrent-1.3.4-7jpp.ep1.6.el4.noarch.rpm     635d11a6d386397c21a1474b943e663c
concurrent-1.3.4-7jpp.ep1.6.el4.noarch.rpm     635d11a6d386397c21a1474b943e663c
glassfish-jaf-1.1.0-0jpp.ep1.10.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    12d9a471dbe7db35aefcb6b7d4931f2a
glassfish-jaf-1.1.0-0jpp.ep1.10.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    12d9a471dbe7db35aefcb6b7d4931f2a
glassfish-javamail-1.4.0-0jpp.ep1.8.noarch.rpm
File outdated by:  RHSA-2008:0833
    db7bb41ad5545a383d8d07c6c024498a
glassfish-javamail-1.4.0-0jpp.ep1.8.noarch.rpm
File outdated by:  RHSA-2008:0833
    db7bb41ad5545a383d8d07c6c024498a
glassfish-jsf-1.2_04-1.p02.0jpp.ep1.18.noarch.rpm
File outdated by:  RHSA-2008:0825
    8141405089b2a57c1e911b1ccc0229c2
glassfish-jsf-1.2_04-1.p02.0jpp.ep1.18.noarch.rpm
File outdated by:  RHSA-2008:0825
    8141405089b2a57c1e911b1ccc0229c2
glassfish-jstl-1.2.0-0jpp.ep1.2.noarch.rpm
File outdated by:  RHSA-2008:0833
    5b982e27f3df910200a941fb9c37bbfc
glassfish-jstl-1.2.0-0jpp.ep1.2.noarch.rpm
File outdated by:  RHSA-2008:0833
    5b982e27f3df910200a941fb9c37bbfc
hibernate3-annotations-3.2.1-1.patch02.1jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    fde4041a6d739b5347fa14cd4ccb11f1
hibernate3-annotations-3.2.1-1.patch02.1jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    fde4041a6d739b5347fa14cd4ccb11f1
hibernate3-annotations-javadoc-3.2.1-1.patch02.1jpp.ep1.2.el4.noarch
File outdated by:  RHSA-2008:0833
    c8f4390e25192407b499b9ecd35731b6
hibernate3-annotations-javadoc-3.2.1-1.patch02.1jpp.ep1.2.el4.noarch
File outdated by:  RHSA-2008:0833
    c8f4390e25192407b499b9ecd35731b6
hibernate3-entitymanager-3.2.1-1jpp.ep1.6.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    8da4316ff579a01393ba41a881212b94
hibernate3-entitymanager-3.2.1-1jpp.ep1.6.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    8da4316ff579a01393ba41a881212b94
hibernate3-entitymanager-javadoc-3.2.1-1jpp.ep1.6.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    46cfce8b0732738baeee8d949c9ba577
hibernate3-entitymanager-javadoc-3.2.1-1jpp.ep1.6.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    46cfce8b0732738baeee8d949c9ba577
hibernate3-javadoc-3.2.4-1.SP1_CP02.0jpp.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    427fd3e8c9572e2744e4a5982920470e
hibernate3-javadoc-3.2.4-1.SP1_CP02.0jpp.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    427fd3e8c9572e2744e4a5982920470e
hsqldb-1.8.0.8-2.patch01.1jpp.ep1.1.noarch.rpm     e2614d246bfc9a33f2ba386495c25dc9
hsqldb-1.8.0.8-2.patch01.1jpp.ep1.1.noarch.rpm     e2614d246bfc9a33f2ba386495c25dc9
jacorb-2.3.0-1jpp.ep1.4.noarch.rpm     51d81b51fe7e3aed40da1108a18027e1
jacorb-2.3.0-1jpp.ep1.4.noarch.rpm     51d81b51fe7e3aed40da1108a18027e1
jboss-aop-1.5.5-1.CP01.0jpp.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    72944b7bb519111780acf3bf19c612ff
jboss-aop-1.5.5-1.CP01.0jpp.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    72944b7bb519111780acf3bf19c612ff
jboss-cache-1.4.1-4.SP8_CP01.1jpp.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    acf78f7b8edc26c8094dabd2a06cedf8
jboss-cache-1.4.1-4.SP8_CP01.1jpp.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    acf78f7b8edc26c8094dabd2a06cedf8
jboss-common-1.2.1-0jpp.ep1.2.noarch.rpm     86b7be11159237e90234c7f282a46eb4
jboss-common-1.2.1-0jpp.ep1.2.noarch.rpm     86b7be11159237e90234c7f282a46eb4
jboss-remoting-2.2.2-3.SP4.0jpp.ep1.1.noarch.rpm
File outdated by:  RHSA-2008:0833
    d129c48173437d333406da84a3ae11c1
jboss-remoting-2.2.2-3.SP4.0jpp.ep1.1.noarch.rpm
File outdated by:  RHSA-2008:0833
    d129c48173437d333406da84a3ae11c1
jboss-seam-1.2.1-1.ep1.3.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    1c853c6436981f419554a34a852906c3
jboss-seam-1.2.1-1.ep1.3.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    1c853c6436981f419554a34a852906c3
jboss-seam-docs-1.2.1-1.ep1.3.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    bb6c7fc0e25305ef117a234ab2da2605
jboss-seam-docs-1.2.1-1.ep1.3.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    bb6c7fc0e25305ef117a234ab2da2605
jbossas-4.2.0-3.GA_CP02.ep1.3.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    2ec2056ffe675a088e51e586824d4fc8
jbossas-4.2.0-3.GA_CP02.ep1.3.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    2ec2056ffe675a088e51e586824d4fc8
jbossweb-2.0.0-3.CP05.0jpp.ep1.1.noarch.rpm
File outdated by:  RHSA-2008:0877
    8e96f96c70039b8381796d9a69091617
jbossweb-2.0.0-3.CP05.0jpp.ep1.1.noarch.rpm
File outdated by:  RHSA-2008:0877
    8e96f96c70039b8381796d9a69091617
jbossws-jboss42-1.2.1-0jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    5470ea7a5be500656ddedaef79b47a20
jbossws-jboss42-1.2.1-0jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    5470ea7a5be500656ddedaef79b47a20
jbossws-wsconsume-impl-2.0.0-0jpp.ep1.3.noarch.rpm     4104d7c2ec376d430c419f41fe927b65
jbossws-wsconsume-impl-2.0.0-0jpp.ep1.3.noarch.rpm     4104d7c2ec376d430c419f41fe927b65
jbossxb-1.0.0-2.SP1.0jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    e63bc3e28ebbfbda1add7da00233b75e
jbossxb-1.0.0-2.SP1.0jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    e63bc3e28ebbfbda1add7da00233b75e
jcommon-1.0.12-1jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    35ce9727d1b167d0b578f004d8e8c27e
jcommon-1.0.12-1jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    35ce9727d1b167d0b578f004d8e8c27e
jfreechart-1.0.9-1jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    034064e56cf3b84da7edaf6af9f65043
jfreechart-1.0.9-1jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    034064e56cf3b84da7edaf6af9f65043
jgroups-2.4.1-1.SP4.0jpp.ep1.2.noarch.rpm
File outdated by:  RHSA-2008:0825
    4394510d5dae6166bcaa5f2765e62cc5
jgroups-2.4.1-1.SP4.0jpp.ep1.2.noarch.rpm
File outdated by:  RHSA-2008:0825
    4394510d5dae6166bcaa5f2765e62cc5
rh-eap-docs-4.2.0-3.GA_CP02.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    a831356bbbd5a4cab67e7b6e329fb50c
rh-eap-docs-4.2.0-3.GA_CP02.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    a831356bbbd5a4cab67e7b6e329fb50c
rh-eap-docs-examples-4.2.0-3.GA_CP02.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    4d4894e5e11d63099b65ff808739581b
rh-eap-docs-examples-4.2.0-3.GA_CP02.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    4d4894e5e11d63099b65ff808739581b
wsdl4j-1.6.2-1jpp.ep1.8.noarch.rpm     370476987105866f2f7dfdb272ed054a
wsdl4j-1.6.2-1jpp.ep1.8.noarch.rpm     370476987105866f2f7dfdb272ed054a
 
x86_64:
concurrent-1.3.4-7jpp.ep1.6.el4.noarch.rpm     635d11a6d386397c21a1474b943e663c
concurrent-1.3.4-7jpp.ep1.6.el4.noarch.rpm     635d11a6d386397c21a1474b943e663c
glassfish-jaf-1.1.0-0jpp.ep1.10.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    12d9a471dbe7db35aefcb6b7d4931f2a
glassfish-jaf-1.1.0-0jpp.ep1.10.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    12d9a471dbe7db35aefcb6b7d4931f2a
glassfish-javamail-1.4.0-0jpp.ep1.8.noarch.rpm
File outdated by:  RHSA-2008:0833
    db7bb41ad5545a383d8d07c6c024498a
glassfish-javamail-1.4.0-0jpp.ep1.8.noarch.rpm
File outdated by:  RHSA-2008:0833
    db7bb41ad5545a383d8d07c6c024498a
glassfish-jsf-1.2_04-1.p02.0jpp.ep1.18.noarch.rpm
File outdated by:  RHSA-2008:0825
    8141405089b2a57c1e911b1ccc0229c2
glassfish-jsf-1.2_04-1.p02.0jpp.ep1.18.noarch.rpm
File outdated by:  RHSA-2008:0825
    8141405089b2a57c1e911b1ccc0229c2
glassfish-jstl-1.2.0-0jpp.ep1.2.noarch.rpm
File outdated by:  RHSA-2008:0833
    5b982e27f3df910200a941fb9c37bbfc
glassfish-jstl-1.2.0-0jpp.ep1.2.noarch.rpm
File outdated by:  RHSA-2008:0833
    5b982e27f3df910200a941fb9c37bbfc
hibernate3-annotations-3.2.1-1.patch02.1jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    fde4041a6d739b5347fa14cd4ccb11f1
hibernate3-annotations-3.2.1-1.patch02.1jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    fde4041a6d739b5347fa14cd4ccb11f1
hibernate3-annotations-javadoc-3.2.1-1.patch02.1jpp.ep1.2.el4.noarch
File outdated by:  RHSA-2008:0833
    c8f4390e25192407b499b9ecd35731b6
hibernate3-annotations-javadoc-3.2.1-1.patch02.1jpp.ep1.2.el4.noarch
File outdated by:  RHSA-2008:0833
    c8f4390e25192407b499b9ecd35731b6
hibernate3-entitymanager-3.2.1-1jpp.ep1.6.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    8da4316ff579a01393ba41a881212b94
hibernate3-entitymanager-3.2.1-1jpp.ep1.6.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    8da4316ff579a01393ba41a881212b94
hibernate3-entitymanager-javadoc-3.2.1-1jpp.ep1.6.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    46cfce8b0732738baeee8d949c9ba577
hibernate3-entitymanager-javadoc-3.2.1-1jpp.ep1.6.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    46cfce8b0732738baeee8d949c9ba577
hibernate3-javadoc-3.2.4-1.SP1_CP02.0jpp.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    427fd3e8c9572e2744e4a5982920470e
hibernate3-javadoc-3.2.4-1.SP1_CP02.0jpp.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    427fd3e8c9572e2744e4a5982920470e
hsqldb-1.8.0.8-2.patch01.1jpp.ep1.1.noarch.rpm     e2614d246bfc9a33f2ba386495c25dc9
hsqldb-1.8.0.8-2.patch01.1jpp.ep1.1.noarch.rpm     e2614d246bfc9a33f2ba386495c25dc9
jacorb-2.3.0-1jpp.ep1.4.noarch.rpm     51d81b51fe7e3aed40da1108a18027e1
jacorb-2.3.0-1jpp.ep1.4.noarch.rpm     51d81b51fe7e3aed40da1108a18027e1
jboss-aop-1.5.5-1.CP01.0jpp.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    72944b7bb519111780acf3bf19c612ff
jboss-aop-1.5.5-1.CP01.0jpp.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    72944b7bb519111780acf3bf19c612ff
jboss-cache-1.4.1-4.SP8_CP01.1jpp.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    acf78f7b8edc26c8094dabd2a06cedf8
jboss-cache-1.4.1-4.SP8_CP01.1jpp.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    acf78f7b8edc26c8094dabd2a06cedf8
jboss-common-1.2.1-0jpp.ep1.2.noarch.rpm     86b7be11159237e90234c7f282a46eb4
jboss-common-1.2.1-0jpp.ep1.2.noarch.rpm     86b7be11159237e90234c7f282a46eb4
jboss-remoting-2.2.2-3.SP4.0jpp.ep1.1.noarch.rpm
File outdated by:  RHSA-2008:0833
    d129c48173437d333406da84a3ae11c1
jboss-remoting-2.2.2-3.SP4.0jpp.ep1.1.noarch.rpm
File outdated by:  RHSA-2008:0833
    d129c48173437d333406da84a3ae11c1
jboss-seam-1.2.1-1.ep1.3.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    1c853c6436981f419554a34a852906c3
jboss-seam-1.2.1-1.ep1.3.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    1c853c6436981f419554a34a852906c3
jboss-seam-docs-1.2.1-1.ep1.3.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    bb6c7fc0e25305ef117a234ab2da2605
jboss-seam-docs-1.2.1-1.ep1.3.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    bb6c7fc0e25305ef117a234ab2da2605
jbossas-4.2.0-3.GA_CP02.ep1.3.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    2ec2056ffe675a088e51e586824d4fc8
jbossas-4.2.0-3.GA_CP02.ep1.3.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    2ec2056ffe675a088e51e586824d4fc8
jbossweb-2.0.0-3.CP05.0jpp.ep1.1.noarch.rpm
File outdated by:  RHSA-2008:0877
    8e96f96c70039b8381796d9a69091617
jbossweb-2.0.0-3.CP05.0jpp.ep1.1.noarch.rpm
File outdated by:  RHSA-2008:0877
    8e96f96c70039b8381796d9a69091617
jbossws-jboss42-1.2.1-0jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    5470ea7a5be500656ddedaef79b47a20
jbossws-jboss42-1.2.1-0jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    5470ea7a5be500656ddedaef79b47a20
jbossws-wsconsume-impl-2.0.0-0jpp.ep1.3.noarch.rpm     4104d7c2ec376d430c419f41fe927b65
jbossws-wsconsume-impl-2.0.0-0jpp.ep1.3.noarch.rpm     4104d7c2ec376d430c419f41fe927b65
jbossxb-1.0.0-2.SP1.0jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    e63bc3e28ebbfbda1add7da00233b75e
jbossxb-1.0.0-2.SP1.0jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    e63bc3e28ebbfbda1add7da00233b75e
jcommon-1.0.12-1jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    35ce9727d1b167d0b578f004d8e8c27e
jcommon-1.0.12-1jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    35ce9727d1b167d0b578f004d8e8c27e
jfreechart-1.0.9-1jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    034064e56cf3b84da7edaf6af9f65043
jfreechart-1.0.9-1jpp.ep1.2.el4.noarch.rpm
File outdated by:  RHSA-2008:0825
    034064e56cf3b84da7edaf6af9f65043
jgroups-2.4.1-1.SP4.0jpp.ep1.2.noarch.rpm
File outdated by:  RHSA-2008:0825
    4394510d5dae6166bcaa5f2765e62cc5
jgroups-2.4.1-1.SP4.0jpp.ep1.2.noarch.rpm
File outdated by:  RHSA-2008:0825
    4394510d5dae6166bcaa5f2765e62cc5
rh-eap-docs-4.2.0-3.GA_CP02.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    a831356bbbd5a4cab67e7b6e329fb50c
rh-eap-docs-4.2.0-3.GA_CP02.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    a831356bbbd5a4cab67e7b6e329fb50c
rh-eap-docs-examples-4.2.0-3.GA_CP02.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    4d4894e5e11d63099b65ff808739581b
rh-eap-docs-examples-4.2.0-3.GA_CP02.ep1.1.el4.noarch.rpm
File outdated by:  RHSA-2008:0833
    4d4894e5e11d63099b65ff808739581b
wsdl4j-1.6.2-1jpp.ep1.8.noarch.rpm     370476987105866f2f7dfdb272ed054a
wsdl4j-1.6.2-1jpp.ep1.8.noarch.rpm     370476987105866f2f7dfdb272ed054a
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

299801 - CVE-2007-4575 OpenOffice.org-base allows Denial-of-Service and command injection
421081 - CVE-2007-6306 JFreeChart: XSS vulnerabilities in the image map feature
426206 - CVE-2007-6433 EJBQL injection via 'order' parameter


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/