Skip to navigation

Security Advisory Low: JBoss Enterprise Application Platform 4.3.0CP02 security update

Advisory: RHSA-2008:0832-5
Type: Security Advisory
Severity: Low
Issued on: 2008-09-22
Last updated on: 2008-09-22
Affected Products: JBoss Enterprise Application Platform 4.3.0 EL5
CVEs (cve.mitre.org): CVE-2007-5342
CVE-2008-3519

Details

Updated JBoss Enterprise Application Platform (JBEAP) 4.3 packages that fix
various security issues are now available for Red Hat Enterprise Linux 5 as
JBEAP 4.3.0.CP02.

This update has been rated as having low security impact by the Red Hat
Security Response Team.

JBoss Enterprise Application Platform is the market leading platform for
innovative and scalable Java applications; integrating the JBoss
Application Server, with JBoss Hibernate and JBoss Seam into a complete,
simple enterprise solution.

This release of JBEAP for Red Hat Enterprise Linux 5 serves as a
replacement to JBEAP 4.3.0.CP01.

These updated packages include bug fixes and enhancements which are
detailed in the release notes. The link to the release notes is available
below in the References section.

The following security issues are also fixed with this release:

The default security policy in the JULI logging component did not restrict
access permissions to files. This could be misused by untrusted web
applications to access and write arbitrary files in the context of the
tomcat process. (CVE-2007-5342)

The property that controls the download of server classes was set to "true"
in the "production" configuration. When the class download service is bound
to an external interface, a remote attacker was able to download arbitrary
class files from the server class path. (CVE-2008-3519)

Warning: before applying this update, please backup the JBEAP
"server/[configuration]/deploy/" directory, and any other customized
configuration files.

All users of JBEAP 4.3 on Red Hat Enterprise Linux 5 are advised to upgrade
to these updated packages, which resolve these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

JBoss Enterprise Application Platform 4.3.0 EL5

SRPMS:
glassfish-jaf-1.1.0-0jpp.ep1.12.el5.1.src.rpm     MD5: ecc952c4fdd0d6a07187d96d35ab6e15
glassfish-javamail-1.4.0-0jpp.ep1.10.el5.src.rpm     MD5: e911f8de41e41da99f2cbb137593deb4
glassfish-jaxb-2.1.4-1jpp.ep1.4.el5.2.src.rpm
File outdated by:  RHSA-2010:0938
    MD5: 2fb809525c659176289d303474363e3f
glassfish-jaxws-2.1.1-1jpp.ep1.3.el5.src.rpm
File outdated by:  RHSA-2010:0938
    MD5: a94b0d9ce93880763eb12c9fe5ee6279
glassfish-jstl-1.2.0-0jpp.ep1.10.el5.src.rpm     MD5: a64ff787cba38f2c34da9462eb44fcef
hibernate3-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: 5cc82b03fe6d5f7a13f733134de916f5
hibernate3-annotations-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: 5e8c132d3b0999ee52d98540103cc197
hibernate3-commons-annotations-0.0.0-1.1jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1145
    MD5: fb212e17a3f95e9792d4a1b41c3790bd
hibernate3-entitymanager-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.src.rpm
File outdated by:  RHSA-2009:1649
    MD5: fd0b278bc64b10c7e56f17dc406c0213
hibernate3-validator-0.0.0-1.1jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1145
    MD5: 2cd9de808778efc1479f37100b52fbf8
javassist-3.8.0-1jpp.ep1.2.el5.src.rpm
File outdated by:  RHSA-2010:0938
    MD5: d409502daf764ba5d1355acafef6922b
jboss-aop-1.5.5-2.CP02.0jpp.ep1.2.el5.src.rpm
File outdated by:  RHSA-2010:0379
    MD5: dcdffd073694b86193af31745cfe8504
jboss-jaxr-1.2.0-SP1.0jpp.ep1.4.el5.src.rpm
File outdated by:  RHSA-2009:0349
    MD5: 423fbf03f00657b24b2b4286fab18ca1
jboss-messaging-1.4.0-1.SP3_CP03.0jpp.ep1.3.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: 8ccea35d8f9798f271c771d0f88fa054
jboss-remoting-2.2.2-3.SP9.0jpp.ep1.2.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: 803a5b9c45e9bde30ba40cd75e5f85d3
jboss-seam-1.2.1-3.JBPAPP_4_3_0_GA.ep1.7.el5.1.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: 8cd642d4659e82c4d15495916ab8e285
jbossas-4.3.0-2.GA_CP02.ep1.10.el5.2.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: b49ff5d10314f9c7f75ad2f94a6d30b4
jbossts-4.2.3-1.SP5_CP02.1jpp.ep1.2.el5.src.rpm
File outdated by:  RHSA-2010:0938
    MD5: de6e846f2d0701ac5274814862342395
jbossweb-2.0.0-4.CP06.0jpp.ep1.1.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: 7f30a03a063327c0e02cc2281775ac69
jbossws-2.0.1-2.SP2_CP03.0jpp.ep1.1.el5.1.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: c1c09905202fef630f6845f78805448a
jbossws-common-1.0.0-1.GA_CP01.0jpp.ep1.3.el5.src.rpm
File outdated by:  RHSA-2011:1306
    MD5: e83c9b6057bf59f2b4b09bcde4fd91f1
jbossws-framework-2.0.1-0jpp.ep1.11.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: eae1ae342d41a8615fe9862f8b5b4819
jbossxb-1.0.0-2.SP3.0jpp.ep1.3.el5.1.src.rpm     MD5: 4ae55098e3705f10a75f550786e8c7c2
rh-eap-docs-4.3.0-2.GA_CP02.ep1.6.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: cef457ebd2015772f7a798b31cebef0a
 
IA-32:
glassfish-jaf-1.1.0-0jpp.ep1.12.el5.1.noarch.rpm     MD5: fcd6e3466f529b88be27d3b04847351c
glassfish-javamail-1.4.0-0jpp.ep1.10.el5.noarch.rpm     MD5: 31e5d10a0c8a472fe000d17e993e76cb
glassfish-jaxb-2.1.4-1jpp.ep1.4.el5.2.noarch.rpm
File outdated by:  RHSA-2010:0938
    MD5: bb902e790e4cbb6bb7eae828116cb8c4
glassfish-jaxb-javadoc-2.1.4-1jpp.ep1.4.el5.2.noarch.rpm
File outdated by:  RHSA-2009:1649
    MD5: edbe35b0841fd21fd9556b83333e2ead
glassfish-jaxws-2.1.1-1jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2010:0938
    MD5: 662b850f8b8a490b62c1494787ce6999
glassfish-jaxws-javadoc-2.1.1-1jpp.ep1.3.el5.noarch.rpm     MD5: aa3b3c9e4b3882d1dedc312d7639d0a8
glassfish-jstl-1.2.0-0jpp.ep1.10.el5.noarch.rpm     MD5: 06318705731553b95e270a3ce82851a8
hibernate3-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: a74d3a39ac2307211d8c672b73006486
hibernate3-annotations-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 69c4abada0f594bd7c8984aea3db3828
hibernate3-annotations-javadoc-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 4a4117eb1bebdc9bcae795c8698ceb5a
hibernate3-commons-annotations-0.0.0-1.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    MD5: 0227a464af39dc96c930fb07043119df
hibernate3-entitymanager-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2009:1649
    MD5: abf2d20fff631a10e725711278f8b1aa
hibernate3-entitymanager-javadoc-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2009:1649
    MD5: 397d1cad4cf4f5b7efaa07bb046fa43b
hibernate3-javadoc-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: eee079be6f669b59dd98e2d18958cc4e
hibernate3-validator-0.0.0-1.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    MD5: 608f02546f6e9ddb342f00166edb4d42
javassist-3.8.0-1jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2010:0938
    MD5: 84a67276a2a20d681990d16baaa30b88
jboss-aop-1.5.5-2.CP02.0jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2010:0379
    MD5: 111150ed4eb61a64c1dd366e7b455db9
jboss-jaxr-1.2.0-SP1.0jpp.ep1.4.el5.noarch.rpm
File outdated by:  RHSA-2009:0349
    MD5: ecb400c230947db9db52829b318a4e1f
jboss-messaging-1.4.0-1.SP3_CP03.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: c8ec4dd5f554847f2429220b748da1fb
jboss-remoting-2.2.2-3.SP9.0jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 5876e43f9ad0dce64bcb4187c1c89b37
jboss-seam-1.2.1-3.JBPAPP_4_3_0_GA.ep1.7.el5.1.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 5fad7a7ef5695fb1ab6119a2a7e5e990
jboss-seam-docs-1.2.1-3.JBPAPP_4_3_0_GA.ep1.7.el5.1.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 0e9d6160c00141060a6758d23172b725
jbossas-4.3.0-2.GA_CP02.ep1.10.el5.2.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 8d9a5365abba5a766f7af476936ade42
jbossts-4.2.3-1.SP5_CP02.1jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2010:0938
    MD5: 62ea7720386c59e804f3073515a6babe
jbossweb-2.0.0-4.CP06.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 49662e753623f104d5fa9474d15bd9f2
jbossws-2.0.1-2.SP2_CP03.0jpp.ep1.1.el5.1.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: ecf1b28de43743fb6a1edc83e9b7c4e2
jbossws-common-1.0.0-1.GA_CP01.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2011:1306
    MD5: 3d3d8e1e9454f859ceaf4e4382b04e21
jbossws-framework-2.0.1-0jpp.ep1.11.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 5726838256bf62f487ba666d7f99fd83
jbossxb-1.0.0-2.SP3.0jpp.ep1.3.el5.1.noarch.rpm     MD5: 436ef36010965564a42fbe3b505b316d
rh-eap-docs-4.3.0-2.GA_CP02.ep1.6.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: a098d7fc0a83fd7c372750634f3eaeab
 
x86_64:
glassfish-jaf-1.1.0-0jpp.ep1.12.el5.1.noarch.rpm     MD5: fcd6e3466f529b88be27d3b04847351c
glassfish-javamail-1.4.0-0jpp.ep1.10.el5.noarch.rpm     MD5: 31e5d10a0c8a472fe000d17e993e76cb
glassfish-jaxb-2.1.4-1jpp.ep1.4.el5.2.noarch.rpm
File outdated by:  RHSA-2010:0938
    MD5: bb902e790e4cbb6bb7eae828116cb8c4
glassfish-jaxb-javadoc-2.1.4-1jpp.ep1.4.el5.2.noarch.rpm
File outdated by:  RHSA-2009:1649
    MD5: edbe35b0841fd21fd9556b83333e2ead
glassfish-jaxws-2.1.1-1jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2010:0938
    MD5: 662b850f8b8a490b62c1494787ce6999
glassfish-jaxws-javadoc-2.1.1-1jpp.ep1.3.el5.noarch.rpm     MD5: aa3b3c9e4b3882d1dedc312d7639d0a8
glassfish-jstl-1.2.0-0jpp.ep1.10.el5.noarch.rpm     MD5: 06318705731553b95e270a3ce82851a8
hibernate3-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: a74d3a39ac2307211d8c672b73006486
hibernate3-annotations-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 69c4abada0f594bd7c8984aea3db3828
hibernate3-annotations-javadoc-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 4a4117eb1bebdc9bcae795c8698ceb5a
hibernate3-commons-annotations-0.0.0-1.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    MD5: 0227a464af39dc96c930fb07043119df
hibernate3-entitymanager-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2009:1649
    MD5: abf2d20fff631a10e725711278f8b1aa
hibernate3-entitymanager-javadoc-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2009:1649
    MD5: 397d1cad4cf4f5b7efaa07bb046fa43b
hibernate3-javadoc-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: eee079be6f669b59dd98e2d18958cc4e
hibernate3-validator-0.0.0-1.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    MD5: 608f02546f6e9ddb342f00166edb4d42
javassist-3.8.0-1jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2010:0938
    MD5: 84a67276a2a20d681990d16baaa30b88
jboss-aop-1.5.5-2.CP02.0jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2010:0379
    MD5: 111150ed4eb61a64c1dd366e7b455db9
jboss-jaxr-1.2.0-SP1.0jpp.ep1.4.el5.noarch.rpm
File outdated by:  RHSA-2009:0349
    MD5: ecb400c230947db9db52829b318a4e1f
jboss-messaging-1.4.0-1.SP3_CP03.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: c8ec4dd5f554847f2429220b748da1fb
jboss-remoting-2.2.2-3.SP9.0jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 5876e43f9ad0dce64bcb4187c1c89b37
jboss-seam-1.2.1-3.JBPAPP_4_3_0_GA.ep1.7.el5.1.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 5fad7a7ef5695fb1ab6119a2a7e5e990
jboss-seam-docs-1.2.1-3.JBPAPP_4_3_0_GA.ep1.7.el5.1.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 0e9d6160c00141060a6758d23172b725
jbossas-4.3.0-2.GA_CP02.ep1.10.el5.2.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 8d9a5365abba5a766f7af476936ade42
jbossts-4.2.3-1.SP5_CP02.1jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2010:0938
    MD5: 62ea7720386c59e804f3073515a6babe
jbossweb-2.0.0-4.CP06.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 49662e753623f104d5fa9474d15bd9f2
jbossws-2.0.1-2.SP2_CP03.0jpp.ep1.1.el5.1.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: ecf1b28de43743fb6a1edc83e9b7c4e2
jbossws-common-1.0.0-1.GA_CP01.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2011:1306
    MD5: 3d3d8e1e9454f859ceaf4e4382b04e21
jbossws-framework-2.0.1-0jpp.ep1.11.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 5726838256bf62f487ba666d7f99fd83
jbossxb-1.0.0-2.SP3.0jpp.ep1.3.el5.1.noarch.rpm     MD5: 436ef36010965564a42fbe3b505b316d
rh-eap-docs-4.3.0-2.GA_CP02.ep1.6.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: a098d7fc0a83fd7c372750634f3eaeab
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

427216 - CVE-2007-5342 Apache Tomcat's default security policy is too open
458713 - Tracker bug for the EAP 4.3.0.cp02 release for RHEL-5
458823 - CVE-2008-3519 JBossEAP allows download of non-EJB class files


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/