Security Advisory Moderate: Red Hat Application Stack v2.2 security and enhancement update

Advisory: RHSA-2008:0966-15
Type: Security Advisory
Severity: Moderate
Issued on: 2008-12-04
Last updated on: 2008-12-11
Affected Products: Red Hat Application Stack v2
OVAL: N/A
CVEs (cve.mitre.org): CVE-2007-6420
CVE-2008-2364
CVE-2008-2939

Details

Red Hat Application Stack v2.2 is now available. This update fixes several
security issues and adds various enhancements.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

[Updated 11th December 2008]
This erratum has been updated to correct a typo in the version number of
the Apache HTTP server packages mentioned in the erratum description.
The proper version of the Apache HTTP server packages shipped with this
erratum is 2.2.10. No changes have been made to the packages.

The Red Hat Application Stack v2.2 is an integrated open source application
stack, that includes Red Hat Enterprise Linux 5 and JBoss Enterprise
Application Platform (EAP) 4.2.

This erratum updates the Apache HTTP Server package to version 2.2.10 which
addresses the following security issues:

A flaw was found in the mod_proxy module. An attacker who has control of
a web server to which requests are being proxied could cause a limited
denial of service due to CPU consumption and stack exhaustion. (CVE-2008-2364)

A flaw was found in the mod_proxy_ftp module. Where Apache is configured
to support ftp-over-httpd proxying, a remote attacker could perform a
cross-site scripting attack. (CVE-2008-2939)

A cross-site request forgery issue was found in the mod_proxy_balancer
module. A remote attacker could cause a denial of service if
mod_proxy_balancer is enabled and an authenticated user is targeted.
(CVE-2007-6420)

The JBoss Enterprise Application Platform (EAP) 4.2 has been updated to
version 4.2.0.CP05.

The following packages were also updated:

* mysql to 5.0.60sp1
* mysql-connector-odbc to 3.51.26r1127
* perl-DBI to 1.607
* perl-DBD-MySQL to 4.008
* perl-DBD-Pg to 1.49
* php-pear to 1.7.2
* postgresql to 8.2.11
* postgresqlclient81 to 8.1.11


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

Red Hat Application Stack v2

SRPMS:
httpd-2.2.10-1.el5s2.src.rpm
File outdated by:  RHSA-2009:1461
    38570f1b483cd994415b01b5acad6ba0
mysql-connector-odbc-3.51.26r1127-1.el5s2.src.rpm
File outdated by:  RHSA-2009:1067
    ac8f031f9d44fd4fd5defe59ae8369d0
perl-DBD-MySQL-4.008-2.el5s2.src.rpm
File outdated by:  RHSA-2009:1461
    64a015aac8492be5196a65e5797c4c1e
perl-DBD-Pg-1.49-4.el5s2.src.rpm
File outdated by:  RHSA-2009:1067
    e0187ccf86166d9af5c2320998571d86
perl-DBI-1.607-3.el5s2.src.rpm
File outdated by:  RHSA-2009:1461
    e30c4abd6da76da377ff6e9a37f01bad
php-pear-1.7.2-2.el5s2.src.rpm
File outdated by:  RHSA-2009:1461
    5fa997276b433e0388af45347555ec62
postgresql-8.2.11-1.el5s2.src.rpm
File outdated by:  RHSA-2009:1461
    d6ea7e4804a373861e1209fdb43167e2
postgresqlclient81-8.1.14-1.el5s2.src.rpm
File outdated by:  RHSA-2009:1067
    bec53e9f1e2d9902044e7934bfea56df
 
IA-32:
httpd-2.2.10-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    9c2d849acb8f5b225eeab074fbb327e4
httpd-devel-2.2.10-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    05b14c74e18a5e5400798d071d70016c
httpd-manual-2.2.10-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    056774a6e2babc6764d3d7f34a3bb90a
mod_ssl-2.2.10-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    a9df08a0c36fb3711ef3f1dbcd770675
mysql-5.0.60sp1-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    5fa522c1b68f5fd55226ab4dfa8e21e3
mysql-bench-5.0.60sp1-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    ea6a9e3a83b668b64951555d9ceeabfe
mysql-cluster-5.0.60sp1-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    e7c72ff09c2f8cac29c63be7d23f2f12
mysql-connector-odbc-3.51.26r1127-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1067
    8707b3f620e9ed6fb114a67f52758beb
mysql-devel-5.0.60sp1-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    36bb0b9660a3e99c83df8f550ae4bfd1
mysql-libs-5.0.60sp1-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    3c38add341ec6b427e9a803e875b2f31
mysql-server-5.0.60sp1-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    d0b341b8ebb614e389f7ef88d4277b16
mysql-test-5.0.60sp1-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    384ef9808647b91cb7cf91052205c9dd
perl-DBD-MySQL-4.008-2.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    de71eb54447093552e99303b00f3cf9c
perl-DBD-Pg-1.49-4.el5s2.i386.rpm
File outdated by:  RHSA-2009:1067
    42352ec33a0a8e0f5b013cb0fb56898c
perl-DBI-1.607-3.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    b11089789d2fe3cdc6c5f854e842834b
php-pear-1.7.2-2.el5s2.noarch.rpm
File outdated by:  RHSA-2009:1461
    acaef4df4b27cb416265e468b6f29c00
postgresql-8.2.11-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    1cd9dc64f3babdd6e8b702c26678beae
postgresql-contrib-8.2.11-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    0ef28f507483caa587c94ed77fab3670
postgresql-devel-8.2.11-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    00a598a6416c316adf8f6ebea86c640e
postgresql-docs-8.2.11-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    7111ea3062339e0174b5e3c5cc4bc493
postgresql-libs-8.2.11-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    45b420e4e0ea19b8bde4f8b0bd32ff99
postgresql-plperl-8.2.11-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    7b48761ffd33760df2bc570057b9d221
postgresql-plpython-8.2.11-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    ff8a6babffb206f7c01e6f0269bdd2b1
postgresql-pltcl-8.2.11-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    769f6d6a550b857b92de09cadc8ff867
postgresql-python-8.2.11-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    2ebbddb31f8018afec383b4b823f1612
postgresql-server-8.2.11-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    46bc1cf851fd8b40427277e95394b80b
postgresql-tcl-8.2.11-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    231fa3319743d9303bae063df274cebd
postgresql-test-8.2.11-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    94f1a38f5f4c405c77f848b522725fd2
postgresqlclient81-8.1.14-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1067
    60f7cfb6a0d1eabe20a48f1a2f3ce4b9
 
x86_64:
httpd-2.2.10-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    ca40bca4f863c7cec3ab6f50cc1e64dd
httpd-devel-2.2.10-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    05b14c74e18a5e5400798d071d70016c
httpd-devel-2.2.10-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    12310ce793736c8412c26a1da997c2c1
httpd-manual-2.2.10-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    4d455942255e37f8bb9bcb19d83317d8
mod_ssl-2.2.10-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    b4d1c53def8f53ac15dc448580326a4e
mysql-5.0.60sp1-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    5fa522c1b68f5fd55226ab4dfa8e21e3
mysql-5.0.60sp1-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    b760458d8cfaef7b0b8e6e455e156ce8
mysql-bench-5.0.60sp1-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    4aebe6cb3a22c9ff28ed692c0dbc8884
mysql-cluster-5.0.60sp1-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    639a7c0abf41366e510f784c443b8fbc
mysql-connector-odbc-3.51.26r1127-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1067
    66eb247d6dde2f3b860d78f0a14e148d
mysql-devel-5.0.60sp1-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    36bb0b9660a3e99c83df8f550ae4bfd1
mysql-devel-5.0.60sp1-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    bbd59a21745c52afa3c0aab8e6409be7
mysql-libs-5.0.60sp1-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    3c38add341ec6b427e9a803e875b2f31
mysql-libs-5.0.60sp1-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    749735f3b57d4b8d7ca4cd1043a56642
mysql-server-5.0.60sp1-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    12393f5e2e3e387a9a068d3cb88192b8
mysql-test-5.0.60sp1-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    175aea3c0f86234d8b73507a050699d9
perl-DBD-MySQL-4.008-2.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    dea44ed08d04495dbff2ba22452562de
perl-DBD-Pg-1.49-4.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1067
    7e84efffc0ef3b5f4ae1f5bd63bb4c22
perl-DBI-1.607-3.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    ebf1fd6a85262dc12989c7eb1e209228
php-pear-1.7.2-2.el5s2.noarch.rpm
File outdated by:  RHSA-2009:1461
    acaef4df4b27cb416265e468b6f29c00
postgresql-8.2.11-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    de85f3487302632ae381ea21e90e662e
postgresql-contrib-8.2.11-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    4e4ad877bad263f6b3b09434e23c5e17
postgresql-devel-8.2.11-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    00a598a6416c316adf8f6ebea86c640e
postgresql-devel-8.2.11-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    c1d5a7ceb445dd8391acff677169dc3b
postgresql-docs-8.2.11-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    ba8dee6817aef3d9f056c4374ce34d09
postgresql-libs-8.2.11-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1461
    45b420e4e0ea19b8bde4f8b0bd32ff99
postgresql-libs-8.2.11-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    2c69ed0fdee0bd0b163e4761a72a2819
postgresql-plperl-8.2.11-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    ed6bda658890779b6ba0129dcafce885
postgresql-plpython-8.2.11-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    dba5bd2c9b9aacaf0eb66baa66a54d10
postgresql-pltcl-8.2.11-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    86625332fadf53fab347a23b6b813d16
postgresql-python-8.2.11-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    59acf075503752c3440f307bcdca6418
postgresql-server-8.2.11-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    694849b11a14db61641f5003e94ce95f
postgresql-tcl-8.2.11-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    c98fe1769009412ae9fb8cf29c7ca101
postgresql-test-8.2.11-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1461
    208d60834ea068ae46bd167562113756
postgresqlclient81-8.1.14-1.el5s2.i386.rpm
File outdated by:  RHSA-2009:1067
    60f7cfb6a0d1eabe20a48f1a2f3ce4b9
postgresqlclient81-8.1.14-1.el5s2.x86_64.rpm
File outdated by:  RHSA-2009:1067
    612963cf6764bc95f7159a65cb4d7836
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

451615 - CVE-2008-2364 httpd: mod_proxy_http DoS via excessive interim responses from the origin server
458250 - CVE-2008-2939 httpd: mod_proxy_ftp globbing XSS
471009 - CVE-2007-6420 mod_proxy_balancer CSRF


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/