Security Advisory Low: JBoss Enterprise Application Platform 4.2.0CP04 security update

Advisory: RHSA-2008:0834-6
Type: Security Advisory
Severity: Low
Issued on: 2008-09-22
Last updated on: 2008-09-22
Affected Products: JBoss Enterprise Application Platform 4.2.0 EL5
OVAL: N/A
CVEs (cve.mitre.org): CVE-2007-5342
CVE-2008-3519

Details

Updated JBoss Enterprise Application Platform (JBEAP) 4.2 packages that fix
various security issues are now available for Red Hat Enterprise Linux 5 as
JBEAP 4.2.0.CP04.

This update has been rated as having low security impact by the Red Hat
Security Response Team.

JBoss Enterprise Application Platform is the market leading platform for
innovative and scalable Java applications; integrating the JBoss
Application Server, with JBoss Hibernate and JBoss Seam into a complete,
simple enterprise solution.

This release of JBEAP for Red Hat Enterprise Linux 5 serves as a
replacement to JBEAP 4.2.0.CP03.

These updated packages include bug fixes and enhancements which are
detailed in the release notes. The link to the release notes is available
below in the References section.

The following security issues are also fixed with this release:

The default security policy in the JULI logging component did not restrict
access permissions to files. This could be misused by untrusted web
applications to access and write arbitrary files in the context of the
tomcat process. (CVE-2007-5342)

The property that controls the download of server classes was set to "true"
in the "production" configuration. When the class download service is bound
to an external interface, a remote attacker was able to download arbitrary
class files from the server class path. (CVE-2008-3519)

Warning: before applying this update, please backup the JBEAP
"server/[configuration]/deploy/" directory, and any other customized
configuration files.

All users of JBEAP 4.2 on Red Hat Enterprise Linux 5 are advised to upgrade
to these updated packages, which resolve these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

JBoss Enterprise Application Platform 4.2.0 EL5

SRPMS:
glassfish-jaf-1.1.0-0jpp.ep1.12.el5.1.src.rpm     ecc952c4fdd0d6a07187d96d35ab6e15
glassfish-javamail-1.4.0-0jpp.ep1.10.el5.src.rpm     e911f8de41e41da99f2cbb137593deb4
glassfish-jstl-1.2.0-0jpp.ep1.10.el5.src.rpm     a64ff787cba38f2c34da9462eb44fcef
hibernate3-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.src.rpm
File outdated by:  RHSA-2009:1143
    5cc82b03fe6d5f7a13f733134de916f5
hibernate3-annotations-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.src.rpm
File outdated by:  RHSA-2009:1143
    5e8c132d3b0999ee52d98540103cc197
hibernate3-commons-annotations-0.0.0-1.1jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1143
    fb212e17a3f95e9792d4a1b41c3790bd
hibernate3-entitymanager-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.src.rpm
File outdated by:  RHSA-2009:1143
    fd0b278bc64b10c7e56f17dc406c0213
hibernate3-validator-0.0.0-1.1jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1143
    2cd9de808778efc1479f37100b52fbf8
javassist-3.8.0-1jpp.ep1.2.el5.src.rpm     d409502daf764ba5d1355acafef6922b
jboss-aop-1.5.5-2.CP02.0jpp.ep1.2.el5.src.rpm
File outdated by:  RHBA-2008:0928
    dcdffd073694b86193af31745cfe8504
jboss-jaxr-1.2.0-SP1.0jpp.ep1.4.el5.src.rpm
File outdated by:  RHSA-2009:0348
    423fbf03f00657b24b2b4286fab18ca1
jboss-remoting-2.2.2-3.SP9.0jpp.ep1.2.el5.src.rpm
File outdated by:  RHSA-2009:1143
    803a5b9c45e9bde30ba40cd75e5f85d3
jboss-seam-1.2.1-1.ep1.9.el5.src.rpm
File outdated by:  RHSA-2009:1143
    97aef1e0799c562d4006814279c56687
jbossas-4.2.0-4.GA_CP04.ep1.7.el5.6.src.rpm
File outdated by:  RHSA-2009:1143
    4d8a38d5858239294385d249e91dd016
jbossts-4.2.3-1.SP5_CP02.1jpp.ep1.2.el5.src.rpm
File outdated by:  RHSA-2009:1143
    de6e846f2d0701ac5274814862342395
jbossweb-2.0.0-4.CP06.0jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1143
    7f30a03a063327c0e02cc2281775ac69
jbossxb-1.0.0-2.SP3.0jpp.ep1.3.el5.1.src.rpm     4ae55098e3705f10a75f550786e8c7c2
rh-eap-docs-4.2.0-4.GA_CP04.ep1.3.el5.src.rpm
File outdated by:  RHSA-2009:1143
    fca7b1dded4c3b0e98438338bc30b1d9
 
IA-32:
glassfish-jaf-1.1.0-0jpp.ep1.12.el5.1.noarch.rpm     fcd6e3466f529b88be27d3b04847351c
glassfish-javamail-1.4.0-0jpp.ep1.10.el5.noarch.rpm     31e5d10a0c8a472fe000d17e993e76cb
glassfish-jstl-1.2.0-0jpp.ep1.10.el5.noarch.rpm     06318705731553b95e270a3ce82851a8
hibernate3-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    a74d3a39ac2307211d8c672b73006486
hibernate3-annotations-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1143
    69c4abada0f594bd7c8984aea3db3828
hibernate3-annotations-javadoc-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1143
    4a4117eb1bebdc9bcae795c8698ceb5a
hibernate3-commons-annotations-0.0.0-1.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    0227a464af39dc96c930fb07043119df
hibernate3-entitymanager-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    abf2d20fff631a10e725711278f8b1aa
hibernate3-entitymanager-javadoc-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    397d1cad4cf4f5b7efaa07bb046fa43b
hibernate3-javadoc-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    eee079be6f669b59dd98e2d18958cc4e
hibernate3-validator-0.0.0-1.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    608f02546f6e9ddb342f00166edb4d42
javassist-3.8.0-1jpp.ep1.2.el5.noarch.rpm     84a67276a2a20d681990d16baaa30b88
jboss-aop-1.5.5-2.CP02.0jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHBA-2008:0928
    111150ed4eb61a64c1dd366e7b455db9
jboss-jaxr-1.2.0-SP1.0jpp.ep1.4.el5.noarch.rpm
File outdated by:  RHSA-2009:0348
    ecb400c230947db9db52829b318a4e1f
jboss-remoting-2.2.2-3.SP9.0jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    5876e43f9ad0dce64bcb4187c1c89b37
jboss-seam-1.2.1-1.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    3416779dbbc17e31b52389907c7d035f
jboss-seam-docs-1.2.1-1.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    881778a20818da5b2928112551e54bd6
jbossas-4.2.0-4.GA_CP04.ep1.7.el5.6.noarch.rpm
File outdated by:  RHSA-2009:1143
    0f43e751114803153fcfe7abef5cdb20
jbossts-4.2.3-1.SP5_CP02.1jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    62ea7720386c59e804f3073515a6babe
jbossweb-2.0.0-4.CP06.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    49662e753623f104d5fa9474d15bd9f2
jbossxb-1.0.0-2.SP3.0jpp.ep1.3.el5.1.noarch.rpm     436ef36010965564a42fbe3b505b316d
rh-eap-docs-4.2.0-4.GA_CP04.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    aa9eaa437cae104ae9918a858abdef69
rh-eap-docs-examples-4.2.0-4.GA_CP04.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    fc1868aeeaab7ac45832966eb5bd6e0b
 
x86_64:
glassfish-jaf-1.1.0-0jpp.ep1.12.el5.1.noarch.rpm     fcd6e3466f529b88be27d3b04847351c
glassfish-javamail-1.4.0-0jpp.ep1.10.el5.noarch.rpm     31e5d10a0c8a472fe000d17e993e76cb
glassfish-jstl-1.2.0-0jpp.ep1.10.el5.noarch.rpm     06318705731553b95e270a3ce82851a8
hibernate3-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    a74d3a39ac2307211d8c672b73006486
hibernate3-annotations-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1143
    69c4abada0f594bd7c8984aea3db3828
hibernate3-annotations-javadoc-3.2.1-4.GA_CP02.1jpp.ep1.7.el5.1.noarch.r
File outdated by:  RHSA-2009:1143
    4a4117eb1bebdc9bcae795c8698ceb5a
hibernate3-commons-annotations-0.0.0-1.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    0227a464af39dc96c930fb07043119df
hibernate3-entitymanager-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    abf2d20fff631a10e725711278f8b1aa
hibernate3-entitymanager-javadoc-3.2.1-2.GA_CP03.1jpp.ep1.9.el5.noarch.r
File outdated by:  RHSA-2009:1143
    397d1cad4cf4f5b7efaa07bb046fa43b
hibernate3-javadoc-3.2.4-1.SP1_CP04.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    eee079be6f669b59dd98e2d18958cc4e
hibernate3-validator-0.0.0-1.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    608f02546f6e9ddb342f00166edb4d42
javassist-3.8.0-1jpp.ep1.2.el5.noarch.rpm     84a67276a2a20d681990d16baaa30b88
jboss-aop-1.5.5-2.CP02.0jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHBA-2008:0928
    111150ed4eb61a64c1dd366e7b455db9
jboss-jaxr-1.2.0-SP1.0jpp.ep1.4.el5.noarch.rpm
File outdated by:  RHSA-2009:0348
    ecb400c230947db9db52829b318a4e1f
jboss-remoting-2.2.2-3.SP9.0jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    5876e43f9ad0dce64bcb4187c1c89b37
jboss-seam-1.2.1-1.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    3416779dbbc17e31b52389907c7d035f
jboss-seam-docs-1.2.1-1.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    881778a20818da5b2928112551e54bd6
jbossas-4.2.0-4.GA_CP04.ep1.7.el5.6.noarch.rpm
File outdated by:  RHSA-2009:1143
    0f43e751114803153fcfe7abef5cdb20
jbossts-4.2.3-1.SP5_CP02.1jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    62ea7720386c59e804f3073515a6babe
jbossweb-2.0.0-4.CP06.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    49662e753623f104d5fa9474d15bd9f2
jbossxb-1.0.0-2.SP3.0jpp.ep1.3.el5.1.noarch.rpm     436ef36010965564a42fbe3b505b316d
rh-eap-docs-4.2.0-4.GA_CP04.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    aa9eaa437cae104ae9918a858abdef69
rh-eap-docs-examples-4.2.0-4.GA_CP04.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    fc1868aeeaab7ac45832966eb5bd6e0b
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

427216 - CVE-2007-5342 Apache Tomcat's default security policy is too open
458711 - Tracker bug for the EAP 4.2.0.cp04 release for RHEL-5.
458823 - CVE-2008-3519 JBossEAP allows download of non-EJB class files


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/