Security Advisory Low: Red Hat Network Proxy Server security update

Advisory: RHSA-2008:0523-1
Type: Security Advisory
Severity: Low
Issued on: 2008-06-30
Last updated on: 2008-06-30
Affected Products: Red Hat Network Proxy (v. 4.2 for RHEL 3)
Red Hat Network Proxy (v. 4.2 for RHEL 4)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2004-0488
CVE-2004-0700
CVE-2004-0885
CVE-2005-3352
CVE-2006-1329
CVE-2006-3918
CVE-2006-5752
CVE-2007-1349
CVE-2007-3304
CVE-2007-4465
CVE-2007-5000
CVE-2007-6388

Details

Red Hat Network Proxy Server version 4.2.3 is now available. This update
includes fixes for a number of security issues in Red Hat Network Proxy
Server components.

This update has been rated as having low security impact by the Red
Hat Security Response Team.

The Red Hat Network Proxy Server 4.2.3 release corrects several security
vulnerabilities in several shipped components. In a typical operating
environment, these components are not exposed to users of Proxy Server in a
vulnerable manner. These security updates will reduce risk in unique Proxy
Server environments.

Multiple flaws were fixed in the Apache HTTPD server. These flaws could
result in a cross-site scripting or denial-of-service attack.
(CVE-2007-6388, CVE-2007-5000, CVE-2007-4465, CVE-2007-3304, CVE-2006-5752,
CVE-2006-3918, CVE-2005-3352)

A denial-of-service flaw was fixed in mod_perl. (CVE-2007-1349)

Multiple flaws in mod_ssl. (CVE-2004-0488, CVE-2004-0700, CVE-2004-0885)

A denial-of-service flaw was fixed in the jabberd server. (CVE-2006-1329)

Users of Red Hat Network Proxy Server 4.2 are advised to upgrade to 4.2.3,
which resolves these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

Red Hat Network Proxy (v. 4.2 for RHEL 3)

IA-32:
jabberd-2.0s10-3.37.rhn.i386.rpm     0a46e522e813a3bfe3535ca160e79d84
rhn-apache-1.3.27-36.rhn.rhel3.i386.rpm     cb3a9fe3d812d4e5b1d0549e8e383b70
rhn-modperl-1.29-16.rhel3.i386.rpm     7993bda4c88dc6c4e1d2ce0cad27a31f
 
Red Hat Network Proxy (v. 4.2 for RHEL 4)

IA-32:
jabberd-2.0s10-3.38.rhn.i386.rpm     440264de62e1ae9823420f65bb300f21
rhn-apache-1.3.27-36.rhn.rhel4.i386.rpm     47d7b59505e01838fc950fff48a10e30
rhn-modperl-1.29-16.rhel4.i386.rpm     b43b815d38624d07da55121b3917a2f3
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

449336 - Bring various components of Proxy Server 4.2 up to date


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/