Security Advisory Moderate: JBoss Enterprise Application Platform 4.2.0CP06 update

Advisory: RHSA-2009:0348-4
Type: Security Advisory
Severity: Moderate
Issued on: 2009-03-06
Last updated on: 2009-03-06
Affected Products: JBoss Enterprise Application Platform 4.2.0 EL5
OVAL: N/A
CVEs (cve.mitre.org): CVE-2009-0027

Details

Updated JBoss Enterprise Application Platform (JBoss EAP) 4.2 packages that
fix various issues are now available for Red Hat Enterprise Linux 5 as
JBEAP 4.2.0.CP06.

This update has been rated as having moderate security impact by the Red Hat
Security Response Team.

JBoss Enterprise Application Platform (JBoss EAP) is the market-leading
platform for innovative and scalable Java applications. JBoss EAP
integrates the JBoss Application Server with JBoss Hibernate and JBoss Seam
into a complete, simple enterprise solution.

This release of JBoss EAP for Red Hat Enterprise Linux 5 serves as a
replacement for JBEAP 4.2.0.CP05.

These updated packages include bug fixes and enhancements which are
detailed in the release notes. The link to the release notes is available
below in the References section.

The following security issue is also fixed with this release:

The request handler in JBossWS did not correctly verify the resource path
when serving WSDL files for custom web service endpoints. This allowed
remote attackers to read arbitrary XML files with the permissions of the
EAP process. (CVE-2009-0027)

Warning: before applying this update, make sure to back up the JBEAP
"server/[configuration]/deploy/" directory, as well as any other customized
configuration files.

All users of JBoss EAP 4.2 on Red Hat Enterprise Linux 5 are advised to
upgrade to these updated packages, which resolve these issues.


Solution

Before applying this update, make sure that all previously-released errata
relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use the Red
Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

JBoss Enterprise Application Platform 4.2.0 EL5

SRPMS:
glassfish-jsf-1.2_10-0jpp.ep1.5.ep5.el5.src.rpm     bfbf4dde9886d260e0f5ff6b3173defa
hibernate3-3.2.4-1.SP1_CP07.0jpp.ep1.14.1.el5.src.rpm
File outdated by:  RHSA-2009:1143
    bf451884a8f2cf43f9349336fcee2afd
jacorb-2.3.0-1jpp.ep1.7.1.el5.src.rpm     f5c0ba66cfbf2fa7fce6928f3a4965a2
jakarta-commons-logging-jboss-1.1-4.1.ep1.el5.src.rpm     778b2d6547856a02ee39eb116cab6a8d
jboss-cache-1.4.1-6.SP11.1.ep1.el5.src.rpm
File outdated by:  RHSA-2009:1143
    7bc4c10b70c215e55571e0edb5bfd927
jboss-jaxr-1.2.0-SP2.0jpp.ep1.3.2.el5.src.rpm     c94c1443bba17f851fce038c360f9a96
jboss-remoting-2.2.2-3.SP11.0jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1143
    0c8be089223becf596311cfdd411fa60
jboss-seam-1.2.1-1.ep1.12.el5.src.rpm
File outdated by:  RHSA-2009:1143
    ef7cb3cd8adad4f00a0570d094786435
jboss-vfs-1.0.0-1.ep1.el5.src.rpm     007d26f8759bb4bedc38d810b3568f70
jbossas-4.2.0-4.GA_CP06.3.1.ep1.el5.src.rpm
File outdated by:  RHSA-2009:1143
    3eb41dc5becd97f76444d6759194ae4f
jbossts-4.2.3-1.SP5_CP04.1jpp.ep1.2.el5.src.rpm
File outdated by:  RHSA-2009:1143
    2877aa6399c43075063fd611e94622b0
jbossweb-2.0.0-6.CP09.0jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1143
    7c8a10ebcd06293394c72e8c942fb5fe
jbossws-jboss42-1.2.1-1.1.ep1.el5.src.rpm     b1cff0f4fea9821ab63aa8b5ec616dd8
jgroups-2.4.5-2.1.ep1.el5.src.rpm
File outdated by:  RHSA-2009:1143
    d6e3ab09842000503654ef7f6473d48a
rh-eap-docs-4.2.0-5.GA_CP06.ep1.3.1.el5.src.rpm
File outdated by:  RHSA-2009:1143
    0ff13e192d5a4edb9223ac83fbdcc3b7
tanukiwrapper-3.2.1-2jpp.ep1.2.el5.src.rpm     7bc966348bfb75b7ab0c30ef7b549290
ws-commons-policy-1.0-2jpp.ep1.7.el5.src.rpm     8ae426c519a21314e84adfba08e796af
ws-scout0-0.7-0.rc2.4.el5.src.rpm     ec19600169aafc4e9a7226b4e5d32cba
 
IA-32:
glassfish-jsf-1.2_10-0jpp.ep1.5.ep5.el5.noarch.rpm     dea5ac4d2fd6d7d871d45c9a73aee38b
hibernate3-3.2.4-1.SP1_CP07.0jpp.ep1.14.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    87bcbe6a6b379370e759d53aa08f0829
hibernate3-javadoc-3.2.4-1.SP1_CP07.0jpp.ep1.14.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    055c09cad5c6c64287c1a1c40b22e47b
jacorb-2.3.0-1jpp.ep1.7.1.el5.noarch.rpm     8ebf14958bbaf2b8dbb280906e34f47f
jakarta-commons-logging-jboss-1.1-4.1.ep1.el5.noarch.rpm     fbdc10023ce06173779978c15e158341
jboss-cache-1.4.1-6.SP11.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    5cc73177dcec37f424792dcd70bcb220
jboss-jaxr-1.2.0-SP2.0jpp.ep1.3.2.el5.noarch.rpm     5b516f5c14cca4688c6f8a235ff1f33b
jboss-remoting-2.2.2-3.SP11.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    f50323b132c1ad6c48864beda7664c64
jboss-seam-1.2.1-1.ep1.12.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    aaa6c135dbe505ab3a999f62381692b4
jboss-seam-docs-1.2.1-1.ep1.12.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    350aebfc6d39e72134e837c61266966e
jboss-vfs-1.0.0-1.ep1.el5.noarch.rpm     0cebf37c147165e0c1f8365476dcbe24
jbossas-4.2.0-4.GA_CP06.3.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    5bd19690b53c65f32b6581776076a9bd
jbossas-4.2.0.GA_CP06-bin-4.2.0-4.GA_CP06.3.1.ep1.el5.noarch.rpm     7baee506d6d488b401589c6f9a3666aa
jbossas-client-4.2.0-4.GA_CP06.3.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    751ea3871c86eaba9b1fe1c7349c4b2c
jbossts-4.2.3-1.SP5_CP04.1jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    7b079e33f782cfc912ca72db9ace452c
jbossweb-2.0.0-6.CP09.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    9fb64ad8cadbc61515a388f113c43911
jbossws-jboss42-1.2.1-1.1.ep1.el5.noarch.rpm     552432c40934d5a64fd6005c88699f1e
jgroups-2.4.5-2.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    8484c3afb2fac56539dd7f33551ec255
rh-eap-docs-4.2.0-5.GA_CP06.ep1.3.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    584756549ddebf7ca726c68a01d1da99
rh-eap-docs-examples-4.2.0-5.GA_CP06.ep1.3.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    21c27ed931c31849ae88923613154f74
tanukiwrapper-3.2.1-2jpp.ep1.2.el5.i386.rpm     9b30a571ea52caf40e7ed2c76921bfe8
ws-commons-policy-1.0-2jpp.ep1.7.el5.noarch.rpm     6417df20c955e47c1d75b548f73de028
ws-scout0-0.7-0.rc2.4.el5.noarch.rpm     8c944bb5d2e25e69447a440888292d50
 
x86_64:
glassfish-jsf-1.2_10-0jpp.ep1.5.ep5.el5.noarch.rpm     dea5ac4d2fd6d7d871d45c9a73aee38b
hibernate3-3.2.4-1.SP1_CP07.0jpp.ep1.14.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    87bcbe6a6b379370e759d53aa08f0829
hibernate3-javadoc-3.2.4-1.SP1_CP07.0jpp.ep1.14.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    055c09cad5c6c64287c1a1c40b22e47b
jacorb-2.3.0-1jpp.ep1.7.1.el5.noarch.rpm     8ebf14958bbaf2b8dbb280906e34f47f
jakarta-commons-logging-jboss-1.1-4.1.ep1.el5.noarch.rpm     fbdc10023ce06173779978c15e158341
jboss-cache-1.4.1-6.SP11.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    5cc73177dcec37f424792dcd70bcb220
jboss-jaxr-1.2.0-SP2.0jpp.ep1.3.2.el5.noarch.rpm     5b516f5c14cca4688c6f8a235ff1f33b
jboss-remoting-2.2.2-3.SP11.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    f50323b132c1ad6c48864beda7664c64
jboss-seam-1.2.1-1.ep1.12.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    aaa6c135dbe505ab3a999f62381692b4
jboss-seam-docs-1.2.1-1.ep1.12.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    350aebfc6d39e72134e837c61266966e
jboss-vfs-1.0.0-1.ep1.el5.noarch.rpm     0cebf37c147165e0c1f8365476dcbe24
jbossas-4.2.0-4.GA_CP06.3.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    5bd19690b53c65f32b6581776076a9bd
jbossas-4.2.0.GA_CP06-bin-4.2.0-4.GA_CP06.3.1.ep1.el5.noarch.rpm     7baee506d6d488b401589c6f9a3666aa
jbossas-client-4.2.0-4.GA_CP06.3.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    751ea3871c86eaba9b1fe1c7349c4b2c
jbossts-4.2.3-1.SP5_CP04.1jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    7b079e33f782cfc912ca72db9ace452c
jbossweb-2.0.0-6.CP09.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    9fb64ad8cadbc61515a388f113c43911
jbossws-jboss42-1.2.1-1.1.ep1.el5.noarch.rpm     552432c40934d5a64fd6005c88699f1e
jgroups-2.4.5-2.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    8484c3afb2fac56539dd7f33551ec255
rh-eap-docs-4.2.0-5.GA_CP06.ep1.3.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    584756549ddebf7ca726c68a01d1da99
rh-eap-docs-examples-4.2.0-5.GA_CP06.ep1.3.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    21c27ed931c31849ae88923613154f74
tanukiwrapper-3.2.1-2jpp.ep1.2.el5.x86_64.rpm     4c1f387890e2a2b0dd05e010bfe61099
ws-commons-policy-1.0-2jpp.ep1.7.el5.noarch.rpm     6417df20c955e47c1d75b548f73de028
ws-scout0-0.7-0.rc2.4.el5.noarch.rpm     8c944bb5d2e25e69447a440888292d50
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

475211 - Tracker bug for the EAP 4.2.0.cp06 release for RHEL-5.
479668 - CVE-2009-0027 JBoss EAP unprivileged local xml file access


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/