Security Advisory Low: JBoss Enterprise Application Platform 4.3.0CP02 security update

Advisory: RHSA-2008:0832-5
Type: Security Advisory
Severity: Low
Issued on: 2008-09-22
Last updated on: 2008-09-22
Affected Products: JBoss Enterprise Application Platform 4.3.0 EL5
OVAL: N/A
CVEs (cve.mitre.org): CVE-2007-5342
CVE-2008-3519

Details

Updated JBoss Enterprise Application Platform (JBEAP) 4.3 packages that fix
various security issues are now available for Red Hat Enterprise Linux 5 as
JBEAP 4.3.0.CP02.

This update has been rated as having low security impact by the Red Hat
Security Response Team.

JBoss Enterprise Application Platform is the market leading platform for
innovative and scalable Java applications; integrating the JBoss
Application Server, with JBoss Hibernate and JBoss Seam into a complete,
simple enterprise solution.

This release of JBEAP for Red Hat Enterprise Linux 5 serves as a
replacement to JBEAP 4.3.0.CP01.

These updated packages include bug fixes and enhancements which are
detailed in the release notes. The link to the release notes is available
below in the References section.

The following security issues are also fixed with this release:

The default security policy in the JULI logging component did not restrict
access permissions to files. This could be misused by untrusted web
applications to access and write arbitrary files in the context of the
tomcat process. (CVE-2007-5342)

The property that controls the download of server classes was set to "true"
in the "production" configuration. When the class download service is bound
to an external interface, a remote attacker was able to download arbitrary
class files from the server class path. (CVE-2008-3519)

Warning: before applying this update, please backup the JBEAP
"server/[configuration]/deploy/" directory, and any other customized
configuration files.

All users of JBEAP 4.3 on Red Hat Enterprise Linux 5 are advised to upgrade
to these updated packages, which resolve these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

JBoss Enterprise Application Platform 4.3.0 EL5

SRPMS:
glassfish-jaf-1.1.0-0jpp.ep1.12.el5.1.src.rpm     ecc952c4fdd0d6a07187d96d35ab6e15
glassfish-javamail-1.4.0-0jpp.ep1.10.el5.src.rpm     e911f8de41e41da99f2cbb137593deb4
glassfish-jaxb-2.1.4-1jpp.ep1.4.el5.2.src.rpm
File outdated by:  RHSA-2009:1145
    2fb809525c659176289d303474363e3f
glassfish-jaxws-2.1.1-1jpp.ep1.3.el5.src.rpm     a94b0d9ce93880763eb12c9fe5ee6279
glassfish-jstl-1.2.0-0jpp.ep1.10.el5.src.rpm     a64ff787cba38f2c34da9462eb44fcef
hibernate3-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.src.rpm
File outdated by:  RHSA-2009:1145
    5cc82b03fe6d5f7a13f733134de916f5
hibernate3-annotations-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.src.rpm
File outdated by:  RHSA-2009:1145
    5e8c132d3b0999ee52d98540103cc197
hibernate3-commons-annotations-0.0.0-1.1jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1145
    fb212e17a3f95e9792d4a1b41c3790bd
hibernate3-entitymanager-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.src.rpm
File outdated by:  RHSA-2009:1145
    fd0b278bc64b10c7e56f17dc406c0213
hibernate3-validator-0.0.0-1.1jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1145
    2cd9de808778efc1479f37100b52fbf8
javassist-3.8.0-1jpp.ep1.2.el5.src.rpm     d409502daf764ba5d1355acafef6922b
jboss-aop-1.5.5-2.CP02.0jpp.ep1.2.el5.src.rpm
File outdated by:  RHBA-2008:0930
    dcdffd073694b86193af31745cfe8504
jboss-jaxr-1.2.0-SP1.0jpp.ep1.4.el5.src.rpm
File outdated by:  RHSA-2009:0349
    423fbf03f00657b24b2b4286fab18ca1
jboss-messaging-1.4.0-1.SP3_CP03.0jpp.ep1.3.el5.src.rpm
File outdated by:  RHBA-2009:1183
    8ccea35d8f9798f271c771d0f88fa054
jboss-remoting-2.2.2-3.SP9.0jpp.ep1.2.el5.src.rpm
File outdated by:  RHSA-2009:1145
    803a5b9c45e9bde30ba40cd75e5f85d3
jboss-seam-1.2.1-3.JBPAPP_4_3_0_GA.ep1.7.el5.1.src.rpm
File outdated by:  RHSA-2009:1145
    8cd642d4659e82c4d15495916ab8e285
jbossas-4.3.0-2.GA_CP02.ep1.10.el5.2.src.rpm
File outdated by:  RHBA-2009:1183
    b49ff5d10314f9c7f75ad2f94a6d30b4
jbossts-4.2.3-1.SP5_CP02.1jpp.ep1.2.el5.src.rpm
File outdated by:  RHSA-2009:1145
    de6e846f2d0701ac5274814862342395
jbossweb-2.0.0-4.CP06.0jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1145
    7f30a03a063327c0e02cc2281775ac69
jbossws-2.0.1-2.SP2_CP03.0jpp.ep1.1.el5.1.src.rpm
File outdated by:  RHSA-2009:1145
    c1c09905202fef630f6845f78805448a
jbossws-common-1.0.0-1.GA_CP01.0jpp.ep1.3.el5.src.rpm
File outdated by:  RHSA-2009:1145
    e83c9b6057bf59f2b4b09bcde4fd91f1
jbossws-framework-2.0.1-0jpp.ep1.11.el5.src.rpm
File outdated by:  RHSA-2009:1145
    eae1ae342d41a8615fe9862f8b5b4819
jbossxb-1.0.0-2.SP3.0jpp.ep1.3.el5.1.src.rpm     4ae55098e3705f10a75f550786e8c7c2
rh-eap-docs-4.3.0-2.GA_CP02.ep1.6.el5.src.rpm
File outdated by:  RHBA-2009:1183
    cef457ebd2015772f7a798b31cebef0a
 
IA-32:
glassfish-jaf-1.1.0-0jpp.ep1.12.el5.1.noarch.rpm     fcd6e3466f529b88be27d3b04847351c
glassfish-javamail-1.4.0-0jpp.ep1.10.el5.noarch.rpm     31e5d10a0c8a472fe000d17e993e76cb
glassfish-jaxb-2.1.4-1jpp.ep1.4.el5.2.noarch.rpm
File outdated by:  RHSA-2009:1145
    bb902e790e4cbb6bb7eae828116cb8c4
glassfish-jaxb-javadoc-2.1.4-1jpp.ep1.4.el5.2.noarch.rpm
File outdated by:  RHSA-2009:1145
    edbe35b0841fd21fd9556b83333e2ead
glassfish-jaxws-2.1.1-1jpp.ep1.3.el5.noarch.rpm     662b850f8b8a490b62c1494787ce6999
glassfish-jaxws-javadoc-2.1.1-1jpp.ep1.3.el5.noarch.rpm     aa3b3c9e4b3882d1dedc312d7639d0a8
glassfish-jstl-1.2.0-0jpp.ep1.10.el5.noarch.rpm     06318705731553b95e270a3ce82851a8
hibernate3-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    a74d3a39ac2307211d8c672b73006486
hibernate3-annotations-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1145
    69c4abada0f594bd7c8984aea3db3828
hibernate3-annotations-javadoc-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1145
    4a4117eb1bebdc9bcae795c8698ceb5a
hibernate3-commons-annotations-0.0.0-1.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    0227a464af39dc96c930fb07043119df
hibernate3-entitymanager-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    abf2d20fff631a10e725711278f8b1aa
hibernate3-entitymanager-javadoc-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    397d1cad4cf4f5b7efaa07bb046fa43b
hibernate3-javadoc-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    eee079be6f669b59dd98e2d18958cc4e
hibernate3-validator-0.0.0-1.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    608f02546f6e9ddb342f00166edb4d42
javassist-3.8.0-1jpp.ep1.2.el5.noarch.rpm     84a67276a2a20d681990d16baaa30b88
jboss-aop-1.5.5-2.CP02.0jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHBA-2008:0930
    111150ed4eb61a64c1dd366e7b455db9
jboss-jaxr-1.2.0-SP1.0jpp.ep1.4.el5.noarch.rpm
File outdated by:  RHSA-2009:0349
    ecb400c230947db9db52829b318a4e1f
jboss-messaging-1.4.0-1.SP3_CP03.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHBA-2009:1183
    c8ec4dd5f554847f2429220b748da1fb
jboss-remoting-2.2.2-3.SP9.0jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    5876e43f9ad0dce64bcb4187c1c89b37
jboss-seam-1.2.1-3.JBPAPP_4_3_0_GA.ep1.7.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1145
    5fad7a7ef5695fb1ab6119a2a7e5e990
jboss-seam-docs-1.2.1-3.JBPAPP_4_3_0_GA.ep1.7.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1145
    0e9d6160c00141060a6758d23172b725
jbossas-4.3.0-2.GA_CP02.ep1.10.el5.2.noarch.rpm
File outdated by:  RHBA-2009:1183
    8d9a5365abba5a766f7af476936ade42
jbossts-4.2.3-1.SP5_CP02.1jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    62ea7720386c59e804f3073515a6babe
jbossweb-2.0.0-4.CP06.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    49662e753623f104d5fa9474d15bd9f2
jbossws-2.0.1-2.SP2_CP03.0jpp.ep1.1.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1145
    ecf1b28de43743fb6a1edc83e9b7c4e2
jbossws-common-1.0.0-1.GA_CP01.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    3d3d8e1e9454f859ceaf4e4382b04e21
jbossws-framework-2.0.1-0jpp.ep1.11.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    5726838256bf62f487ba666d7f99fd83
jbossxb-1.0.0-2.SP3.0jpp.ep1.3.el5.1.noarch.rpm     436ef36010965564a42fbe3b505b316d
rh-eap-docs-4.3.0-2.GA_CP02.ep1.6.el5.noarch.rpm
File outdated by:  RHBA-2009:1183
    a098d7fc0a83fd7c372750634f3eaeab
 
x86_64:
glassfish-jaf-1.1.0-0jpp.ep1.12.el5.1.noarch.rpm     fcd6e3466f529b88be27d3b04847351c
glassfish-javamail-1.4.0-0jpp.ep1.10.el5.noarch.rpm     31e5d10a0c8a472fe000d17e993e76cb
glassfish-jaxb-2.1.4-1jpp.ep1.4.el5.2.noarch.rpm
File outdated by:  RHSA-2009:1145
    bb902e790e4cbb6bb7eae828116cb8c4
glassfish-jaxb-javadoc-2.1.4-1jpp.ep1.4.el5.2.noarch.rpm
File outdated by:  RHSA-2009:1145
    edbe35b0841fd21fd9556b83333e2ead
glassfish-jaxws-2.1.1-1jpp.ep1.3.el5.noarch.rpm     662b850f8b8a490b62c1494787ce6999
glassfish-jaxws-javadoc-2.1.1-1jpp.ep1.3.el5.noarch.rpm     aa3b3c9e4b3882d1dedc312d7639d0a8
glassfish-jstl-1.2.0-0jpp.ep1.10.el5.noarch.rpm     06318705731553b95e270a3ce82851a8
hibernate3-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    a74d3a39ac2307211d8c672b73006486
hibernate3-annotations-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1145
    69c4abada0f594bd7c8984aea3db3828
hibernate3-annotations-javadoc-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.noarch.r
File outdated by:  RHSA-2009:1145
    4a4117eb1bebdc9bcae795c8698ceb5a
hibernate3-commons-annotations-0.0.0-1.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    0227a464af39dc96c930fb07043119df
hibernate3-entitymanager-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    abf2d20fff631a10e725711278f8b1aa
hibernate3-entitymanager-javadoc-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.noarch.r
File outdated by:  RHSA-2009:1145
    397d1cad4cf4f5b7efaa07bb046fa43b
hibernate3-javadoc-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    eee079be6f669b59dd98e2d18958cc4e
hibernate3-validator-0.0.0-1.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    608f02546f6e9ddb342f00166edb4d42
javassist-3.8.0-1jpp.ep1.2.el5.noarch.rpm     84a67276a2a20d681990d16baaa30b88
jboss-aop-1.5.5-2.CP02.0jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHBA-2008:0930
    111150ed4eb61a64c1dd366e7b455db9
jboss-jaxr-1.2.0-SP1.0jpp.ep1.4.el5.noarch.rpm
File outdated by:  RHSA-2009:0349
    ecb400c230947db9db52829b318a4e1f
jboss-messaging-1.4.0-1.SP3_CP03.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHBA-2009:1183
    c8ec4dd5f554847f2429220b748da1fb
jboss-remoting-2.2.2-3.SP9.0jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    5876e43f9ad0dce64bcb4187c1c89b37
jboss-seam-1.2.1-3.JBPAPP_4_3_0_GA.ep1.7.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1145
    5fad7a7ef5695fb1ab6119a2a7e5e990
jboss-seam-docs-1.2.1-3.JBPAPP_4_3_0_GA.ep1.7.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1145
    0e9d6160c00141060a6758d23172b725
jbossas-4.3.0-2.GA_CP02.ep1.10.el5.2.noarch.rpm
File outdated by:  RHBA-2009:1183
    8d9a5365abba5a766f7af476936ade42
jbossts-4.2.3-1.SP5_CP02.1jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    62ea7720386c59e804f3073515a6babe
jbossweb-2.0.0-4.CP06.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    49662e753623f104d5fa9474d15bd9f2
jbossws-2.0.1-2.SP2_CP03.0jpp.ep1.1.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1145
    ecf1b28de43743fb6a1edc83e9b7c4e2
jbossws-common-1.0.0-1.GA_CP01.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    3d3d8e1e9454f859ceaf4e4382b04e21
jbossws-framework-2.0.1-0jpp.ep1.11.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    5726838256bf62f487ba666d7f99fd83
jbossxb-1.0.0-2.SP3.0jpp.ep1.3.el5.1.noarch.rpm     436ef36010965564a42fbe3b505b316d
rh-eap-docs-4.3.0-2.GA_CP02.ep1.6.el5.noarch.rpm
File outdated by:  RHBA-2009:1183
    a098d7fc0a83fd7c372750634f3eaeab
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

427216 - CVE-2007-5342 Apache Tomcat's default security policy is too open
458713 - Tracker bug for the EAP 4.3.0.cp02 release for RHEL-5
458823 - CVE-2008-3519 JBossEAP allows download of non-EJB class files


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/