Important: jboss-seam2 security update
| Advisory: | RHSA-2010:0564-2 |
|---|---|
| Type: | Security Advisory |
| Severity: | Important |
| Issued on: | 2010-07-27 |
| Last updated on: | 2010-07-28 |
| Affected Products: | JBoss Enterprise Application Platform 4.3.0 EL4 JBoss Enterprise Application Platform 4.3.0 EL5 |
| CVEs (cve.mitre.org): |
CVE-2010-1871 |
Details
Updated jboss-seam2 packages that fix one security issue are now available
for JBoss Enterprise Application Platform 4.3 for Red Hat Enterprise Linux
4 and 5.
The Red Hat Security Response Team has rated this update as having
important security impact. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available from the
CVE link in the References section.
[Updated 28 July 2010]
The CVE-2010-1871 description has been updated to reflect that an attacker
does not need to be authenticated to exploit this issue. No changes have
been made to the packages.
The JBoss Seam Framework is an application framework for building web
applications in Java.
An input sanitization flaw was found in the way JBoss Seam processed
certain parametrized JBoss Expression Language (EL) expressions. A remote
attacker could use this flaw to execute arbitrary code via a URL,
containing appended, specially-crafted expression language parameters,
provided to certain applications based on the JBoss Seam framework. Note: A
properly configured and enabled Java Security Manager would prevent
exploitation of this flaw. (CVE-2010-1871)
Red Hat would like to thank Meder Kydyraliev of the Google Security Team
for responsibly reporting this issue.
Users of jboss-seam2 should upgrade to these updated packages, which
contain a backported patch to correct this issue. The JBoss server process
must be restarted for this update to take effect.
Solution
relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259
Updated packages
| JBoss Enterprise Application Platform 4.3.0 EL4 | |
| SRPMS: | |
| jboss-seam2-2.0.2.FP-1.ep1.24.el4.src.rpm File outdated by: RHBA-2011:1297 |
MD5: 6940dd2689c3146fcf504541ef81c84d SHA-256: a58cd06516d59dd79d264fd90450a5346cbf887ce8848f7fbdd5017c4003b1af |
| IA-32: | |
| jboss-seam2-2.0.2.FP-1.ep1.24.el4.noarch.rpm File outdated by: RHBA-2011:1297 |
MD5: 79a0ba189c031b7ea7e46a0f61c592f4 SHA-256: 46fdca2981a6116fc1e59a1e6b4c69c3e0c6e0f93fd8843b99db41c9c6c3a976 |
| jboss-seam2-docs-2.0.2.FP-1.ep1.24.el4.noarch.rpm File outdated by: RHBA-2011:1297 |
MD5: 9c01c4cc2b889c8063eff6d7ea8fc0c9 SHA-256: 18ba8685c97985dfeeff4a892c92eadb08f36fd27fe60b84ce340647f18c7e4f |
| x86_64: | |
| jboss-seam2-2.0.2.FP-1.ep1.24.el4.noarch.rpm File outdated by: RHBA-2011:1297 |
MD5: 79a0ba189c031b7ea7e46a0f61c592f4 SHA-256: 46fdca2981a6116fc1e59a1e6b4c69c3e0c6e0f93fd8843b99db41c9c6c3a976 |
| jboss-seam2-docs-2.0.2.FP-1.ep1.24.el4.noarch.rpm File outdated by: RHBA-2011:1297 |
MD5: 9c01c4cc2b889c8063eff6d7ea8fc0c9 SHA-256: 18ba8685c97985dfeeff4a892c92eadb08f36fd27fe60b84ce340647f18c7e4f |
| JBoss Enterprise Application Platform 4.3.0 EL5 | |
| SRPMS: | |
| jboss-seam2-2.0.2.FP-1.ep1.24.el5.src.rpm File outdated by: RHBA-2011:1298 |
MD5: 85bb7fe6d9502959712e6493fabffc77 SHA-256: 058de117baef1c5bef0ebc2dfdecc7bc140effdd516e10337beecef4af5f8dff |
| IA-32: | |
| jboss-seam2-2.0.2.FP-1.ep1.24.el5.noarch.rpm File outdated by: RHBA-2011:1298 |
MD5: 1a45a61175e402f49ca0b1cd866f477c SHA-256: a0cb3226d7bf94fe6249011e072b3b563f6a72b9e0acf748a9c43f6a36ea6bf5 |
| jboss-seam2-docs-2.0.2.FP-1.ep1.24.el5.noarch.rpm File outdated by: RHBA-2011:1298 |
MD5: 96c60acf421a0a5563b2b66a22576f95 SHA-256: e56cf1c7b66d9b7b2149b09dbb30a0699b3801846ce82173c9b4d1aacf0cac30 |
| x86_64: | |
| jboss-seam2-2.0.2.FP-1.ep1.24.el5.noarch.rpm File outdated by: RHBA-2011:1298 |
MD5: 1a45a61175e402f49ca0b1cd866f477c SHA-256: a0cb3226d7bf94fe6249011e072b3b563f6a72b9e0acf748a9c43f6a36ea6bf5 |
| jboss-seam2-docs-2.0.2.FP-1.ep1.24.el5.noarch.rpm File outdated by: RHBA-2011:1298 |
MD5: 96c60acf421a0a5563b2b66a22576f95 SHA-256: e56cf1c7b66d9b7b2149b09dbb30a0699b3801846ce82173c9b4d1aacf0cac30 |
| (The unlinked packages above are only available from the Red Hat Network) | |
Bugs fixed (see bugzilla for more information)
615956 - CVE-2010-1871 JBoss Seam / Seam2: Improper sanitization of parametrized JBoss EL expressions (ACE)
References
http://www.redhat.com/security/updates/classification/#important
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package
The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/