Security Advisory Low: Red Hat Network Proxy Server security update

Advisory: RHSA-2008:0263-2
Type: Security Advisory
Severity: Low
Issued on: 2008-05-20
Last updated on: 2008-05-20
Affected Products: Red Hat Network Proxy (v. 5.0 for RHEL 4)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2006-1329
CVE-2006-5752
CVE-2007-1349
CVE-2007-3304
CVE-2007-5000
CVE-2007-6388

Details

Red Hat Network Proxy Server version 5.0.2 is now available. This update
includes fixes for a number of security issues in Red Hat Network Proxy
Server components.

This update has been rated as having low security impact by the Red
Hat Security Response Team.

The Red Hat Network Proxy Server 5.0.2 release corrects several security
vulnerabilities in several shipped components. In a typical operating
environment, these components are not exposed to users of Proxy Server in a
vulnerable manner. These security updates will reduce risk in unique Proxy
Server environments.

Multiple flaws were fixed in the Apache HTTPD server. These flaws could
result in a cross-site scripting or denial-of-service attack.
(CVE-2007-6388, CVE-2007-5000, CVE-2007-3304, CVE-2006-5752)

A denial-of-service flaw was fixed in mod_perl. (CVE-2007-1349)

A denial-of-service flaw was fixed in the jabberd server. (CVE-2006-1329)

Users of Red Hat Network Proxy Server 5.0 are advised to upgrade to 5.0.2,
which resolves these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

Red Hat Network Proxy (v. 5.0 for RHEL 4)

IA-32:
jabberd-2.0s10-3.38.rhn.i386.rpm     440264de62e1ae9823420f65bb300f21
rhn-apache-1.3.27-36.rhn.rhel4.i386.rpm     47d7b59505e01838fc950fff48a10e30
rhn-modperl-1.29-16.rhel4.i386.rpm     b43b815d38624d07da55121b3917a2f3
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

240423 - CVE-2007-1349 mod_perl PerlRun denial of service
245111 - CVE-2007-3304 httpd scoreboard lack of PID protection
245112 - CVE-2006-5752 httpd mod_status XSS
419931 - CVE-2007-5000 mod_imagemap XSS
427228 - CVE-2007-6388 apache mod_status cross-site scripting
429254 - CVE-2006-1329 jabberd SASL DoS


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/