Security Advisory Moderate: JBoss Enterprise Application Platform 4.3.0CP04 update

Advisory: RHSA-2009:0349-5
Type: Security Advisory
Severity: Moderate
Issued on: 2009-03-06
Last updated on: 2009-03-06
Affected Products: JBoss Enterprise Application Platform 4.3.0 EL5
OVAL: N/A
CVEs (cve.mitre.org): CVE-2009-0027

Details

Updated JBoss Enterprise Application Platform (JBoss EAP) 4.3 packages that
fix various issues are now available for Red Hat Enterprise Linux 5 as
JBEAP 4.3.0.CP04.

This update has been rated as having moderate security impact by the Red Hat
Security Response Team.

JBoss Enterprise Application Platform (JBoss EAP) is the market-leading
platform for innovative and scalable Java applications. JBoss EAP
integrates the JBoss Application Server with JBoss Hibernate and JBoss Seam
into a complete, simple enterprise solution.

This release of JBoss EAP for Red Hat Enterprise Linux 5 serves as a
replacement for JBEAP 4.3.0.CP03.

These updated packages include bug fixes and enhancements which are
detailed in the release notes. The link to the release notes is available
in the References section of this errata.

The following security issue is also fixed with this release:

The request handler in JBossWS did not correctly verify the resource path
when serving WSDL files for custom web service endpoints. This allowed
remote attackers to read arbitrary XML files with the permissions of the
EAP process. (CVE-2009-0027)

Warning: before applying this update, please back up the JBoss EAP
"server/[configuration]/deploy/" directory, as well as any other customized
configuration files.

All users of JBoss EAP 4.3 on Red Hat Enterprise Linux 5 are advised to
upgrade to these updated packages, which resolve these issues.


Solution

Before applying this update, make sure that all previously-released errata
relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use the Red
Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

JBoss Enterprise Application Platform 4.3.0 EL5

SRPMS:
glassfish-jaxb-2.1.4-1.6.1.ep1.el5.src.rpm
File outdated by:  RHSA-2009:1145
    62a3e4b56ecbca130b2b337837bea59d
glassfish-jsf-1.2_10-0jpp.ep1.5.ep5.el5.src.rpm     bfbf4dde9886d260e0f5ff6b3173defa
hibernate3-3.2.4-1.SP1_CP07.0jpp.ep1.14.1.el5.src.rpm
File outdated by:  RHSA-2009:1145
    bf451884a8f2cf43f9349336fcee2afd
jacorb-2.3.0-1jpp.ep1.7.1.el5.src.rpm     f5c0ba66cfbf2fa7fce6928f3a4965a2
jakarta-commons-logging-jboss-1.1-4.1.ep1.el5.src.rpm     778b2d6547856a02ee39eb116cab6a8d
jboss-cache-1.4.1-6.SP11.1.ep1.el5.src.rpm
File outdated by:  RHSA-2009:1145
    7bc4c10b70c215e55571e0edb5bfd927
jboss-jaxr-1.2.0-SP2.0jpp.ep1.3.2.el5.src.rpm     c94c1443bba17f851fce038c360f9a96
jboss-messaging-1.4.0-2.SP3_CP07.1.ep1.el5.src.rpm
File outdated by:  RHBA-2009:1183
    2916b87f8b61727e3c52e804d8a70250
jboss-remoting-2.2.2-3.SP11.0jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1145
    0c8be089223becf596311cfdd411fa60
jboss-seam-1.2.1-3.JBPAPP_4_3_0_GA.ep1.10.el5.1.src.rpm
File outdated by:  RHSA-2009:1145
    b0cd23e35578cea517e105508b287dc9
jboss-vfs-1.0.0-1.ep1.el5.src.rpm     007d26f8759bb4bedc38d810b3568f70
jbossas-4.3.0-3.GA_CP04.2.1.ep1.el5.src.rpm
File outdated by:  RHBA-2009:1183
    e68b7b4de01b66a7f68bcdbef929fbea
jbossts-4.2.3-1.SP5_CP04.1jpp.ep1.2.el5.src.rpm
File outdated by:  RHSA-2009:1145
    2877aa6399c43075063fd611e94622b0
jbossweb-2.0.0-6.CP09.0jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1145
    7c8a10ebcd06293394c72e8c942fb5fe
jbossws-2.0.1-3.SP2_CP05.3.1.ep1.el5.src.rpm
File outdated by:  RHSA-2009:1145
    462d13ef6a096a6a604b172c46d74b58
jbossws-common-1.0.0-2.GA_CP03.1.ep1.el5.src.rpm
File outdated by:  RHSA-2009:1145
    4d92323ad957e10dceacfc951c5e39d9
jbossws-framework-2.0.1-1.GA_CP03.2.ep1.el5.src.rpm
File outdated by:  RHSA-2009:1145
    bf7fb7cc9fc1c3e0f60b2b7843f5322d
jgroups-2.4.5-2.1.ep1.el5.src.rpm
File outdated by:  RHSA-2009:1145
    d6e3ab09842000503654ef7f6473d48a
rh-eap-docs-4.3.0-4.GA_CP04.ep1.3.1.el5.src.rpm
File outdated by:  RHBA-2009:1183
    853bbb1a57a4c1c14f92319661370453
tanukiwrapper-3.2.1-2jpp.ep1.2.el5.src.rpm     7bc966348bfb75b7ab0c30ef7b549290
ws-commons-policy-1.0-2jpp.ep1.7.el5.src.rpm     8ae426c519a21314e84adfba08e796af
ws-scout0-0.7-0.rc2.4.el5.src.rpm     ec19600169aafc4e9a7226b4e5d32cba
 
IA-32:
glassfish-jaxb-2.1.4-1.6.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    6e5d2a90de6258666451fd8e159aa47b
glassfish-jaxb-javadoc-2.1.4-1.6.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    249adffe061a6a900d7a3445bf79c93d
glassfish-jsf-1.2_10-0jpp.ep1.5.ep5.el5.noarch.rpm     dea5ac4d2fd6d7d871d45c9a73aee38b
hibernate3-3.2.4-1.SP1_CP07.0jpp.ep1.14.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    87bcbe6a6b379370e759d53aa08f0829
hibernate3-javadoc-3.2.4-1.SP1_CP07.0jpp.ep1.14.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    055c09cad5c6c64287c1a1c40b22e47b
jacorb-2.3.0-1jpp.ep1.7.1.el5.noarch.rpm     8ebf14958bbaf2b8dbb280906e34f47f
jakarta-commons-logging-jboss-1.1-4.1.ep1.el5.noarch.rpm     fbdc10023ce06173779978c15e158341
jboss-cache-1.4.1-6.SP11.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    5cc73177dcec37f424792dcd70bcb220
jboss-jaxr-1.2.0-SP2.0jpp.ep1.3.2.el5.noarch.rpm     5b516f5c14cca4688c6f8a235ff1f33b
jboss-messaging-1.4.0-2.SP3_CP07.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2009:1183
    d4ac2c6161a5442e3c3c18d656c0fca3
jboss-remoting-2.2.2-3.SP11.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    f50323b132c1ad6c48864beda7664c64
jboss-seam-1.2.1-3.JBPAPP_4_3_0_GA.ep1.10.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1145
    af6fc0ea4225c099db82eefc3af25ff1
jboss-seam-docs-1.2.1-3.JBPAPP_4_3_0_GA.ep1.10.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1145
    f36c02344ed114b3c19b04db86ce7892
jboss-vfs-1.0.0-1.ep1.el5.noarch.rpm     0cebf37c147165e0c1f8365476dcbe24
jbossas-4.3.0-3.GA_CP04.2.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2009:1183
    26c3e8630379fa19244c4f468d3e7a98
jbossas-4.3.0.GA_CP04-bin-4.3.0-3.GA_CP04.2.1.ep1.el5.noarch.rpm     4d9cc919ff9022a372cb50743a076d7b
jbossas-client-4.3.0-3.GA_CP04.2.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2009:1183
    e93d076b04852d919b2e5fa957f04bfb
jbossts-4.2.3-1.SP5_CP04.1jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    7b079e33f782cfc912ca72db9ace452c
jbossweb-2.0.0-6.CP09.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    9fb64ad8cadbc61515a388f113c43911
jbossws-2.0.1-3.SP2_CP05.3.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    640931a2153940eac7f67307032a3db6
jbossws-common-1.0.0-2.GA_CP03.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    822323f88c3d47029ba7d286d57b95c3
jbossws-framework-2.0.1-1.GA_CP03.2.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    aeb812cf329b3fe9b1728b40a45633f1
jgroups-2.4.5-2.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    8484c3afb2fac56539dd7f33551ec255
rh-eap-docs-4.3.0-4.GA_CP04.ep1.3.1.el5.noarch.rpm
File outdated by:  RHBA-2009:1183
    a1079c47d8048cd512239f78708fbfe3
rh-eap-docs-examples-4.3.0-4.GA_CP04.ep1.3.1.el5.noarch.rpm
File outdated by:  RHBA-2009:1183
    9126da466b64e946cd048459337c3cfb
tanukiwrapper-3.2.1-2jpp.ep1.2.el5.i386.rpm     9b30a571ea52caf40e7ed2c76921bfe8
ws-commons-policy-1.0-2jpp.ep1.7.el5.noarch.rpm     6417df20c955e47c1d75b548f73de028
ws-scout0-0.7-0.rc2.4.el5.noarch.rpm     8c944bb5d2e25e69447a440888292d50
 
x86_64:
glassfish-jaxb-2.1.4-1.6.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    6e5d2a90de6258666451fd8e159aa47b
glassfish-jaxb-javadoc-2.1.4-1.6.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    249adffe061a6a900d7a3445bf79c93d
glassfish-jsf-1.2_10-0jpp.ep1.5.ep5.el5.noarch.rpm     dea5ac4d2fd6d7d871d45c9a73aee38b
hibernate3-3.2.4-1.SP1_CP07.0jpp.ep1.14.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    87bcbe6a6b379370e759d53aa08f0829
hibernate3-javadoc-3.2.4-1.SP1_CP07.0jpp.ep1.14.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    055c09cad5c6c64287c1a1c40b22e47b
jacorb-2.3.0-1jpp.ep1.7.1.el5.noarch.rpm     8ebf14958bbaf2b8dbb280906e34f47f
jakarta-commons-logging-jboss-1.1-4.1.ep1.el5.noarch.rpm     fbdc10023ce06173779978c15e158341
jboss-cache-1.4.1-6.SP11.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    5cc73177dcec37f424792dcd70bcb220
jboss-jaxr-1.2.0-SP2.0jpp.ep1.3.2.el5.noarch.rpm     5b516f5c14cca4688c6f8a235ff1f33b
jboss-messaging-1.4.0-2.SP3_CP07.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2009:1183
    d4ac2c6161a5442e3c3c18d656c0fca3
jboss-remoting-2.2.2-3.SP11.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    f50323b132c1ad6c48864beda7664c64
jboss-seam-1.2.1-3.JBPAPP_4_3_0_GA.ep1.10.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1145
    af6fc0ea4225c099db82eefc3af25ff1
jboss-seam-docs-1.2.1-3.JBPAPP_4_3_0_GA.ep1.10.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1145
    f36c02344ed114b3c19b04db86ce7892
jboss-vfs-1.0.0-1.ep1.el5.noarch.rpm     0cebf37c147165e0c1f8365476dcbe24
jbossas-4.3.0-3.GA_CP04.2.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2009:1183
    26c3e8630379fa19244c4f468d3e7a98
jbossas-4.3.0.GA_CP04-bin-4.3.0-3.GA_CP04.2.1.ep1.el5.noarch.rpm     4d9cc919ff9022a372cb50743a076d7b
jbossas-client-4.3.0-3.GA_CP04.2.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2009:1183
    e93d076b04852d919b2e5fa957f04bfb
jbossts-4.2.3-1.SP5_CP04.1jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    7b079e33f782cfc912ca72db9ace452c
jbossweb-2.0.0-6.CP09.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    9fb64ad8cadbc61515a388f113c43911
jbossws-2.0.1-3.SP2_CP05.3.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    640931a2153940eac7f67307032a3db6
jbossws-common-1.0.0-2.GA_CP03.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    822323f88c3d47029ba7d286d57b95c3
jbossws-framework-2.0.1-1.GA_CP03.2.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    aeb812cf329b3fe9b1728b40a45633f1
jgroups-2.4.5-2.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1145
    8484c3afb2fac56539dd7f33551ec255
rh-eap-docs-4.3.0-4.GA_CP04.ep1.3.1.el5.noarch.rpm
File outdated by:  RHBA-2009:1183
    a1079c47d8048cd512239f78708fbfe3
rh-eap-docs-examples-4.3.0-4.GA_CP04.ep1.3.1.el5.noarch.rpm
File outdated by:  RHBA-2009:1183
    9126da466b64e946cd048459337c3cfb
tanukiwrapper-3.2.1-2jpp.ep1.2.el5.x86_64.rpm     4c1f387890e2a2b0dd05e010bfe61099
ws-commons-policy-1.0-2jpp.ep1.7.el5.noarch.rpm     6417df20c955e47c1d75b548f73de028
ws-scout0-0.7-0.rc2.4.el5.noarch.rpm     8c944bb5d2e25e69447a440888292d50
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

475258 - Tracker bug for the EAP 4.3.0.cp04 release for RHEL-5.
479668 - CVE-2009-0027 JBoss EAP unprivileged local xml file access


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/