Security Advisory Important: jboss-seam2 security update

Advisory: RHSA-2010:0564-2
Type: Security Advisory
Severity: Important
Issued on: 2010-07-27
Last updated on: 2010-07-28
Affected Products: JBoss Enterprise Application Platform 4.3.0 EL4
JBoss Enterprise Application Platform 4.3.0 EL5
CVEs (cve.mitre.org): CVE-2010-1871

Details

Updated jboss-seam2 packages that fix one security issue are now available
for JBoss Enterprise Application Platform 4.3 for Red Hat Enterprise Linux
4 and 5.

The Red Hat Security Response Team has rated this update as having
important security impact. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available from the
CVE link in the References section.

[Updated 28 July 2010]
The CVE-2010-1871 description has been updated to reflect that an attacker
does not need to be authenticated to exploit this issue. No changes have
been made to the packages.

The JBoss Seam Framework is an application framework for building web
applications in Java.

An input sanitization flaw was found in the way JBoss Seam processed
certain parametrized JBoss Expression Language (EL) expressions. A remote
attacker could use this flaw to execute arbitrary code via a URL,
containing appended, specially-crafted expression language parameters,
provided to certain applications based on the JBoss Seam framework. Note: A
properly configured and enabled Java Security Manager would prevent
exploitation of this flaw. (CVE-2010-1871)

Red Hat would like to thank Meder Kydyraliev of the Google Security Team
for responsibly reporting this issue.

Users of jboss-seam2 should upgrade to these updated packages, which
contain a backported patch to correct this issue. The JBoss server process
must be restarted for this update to take effect.


Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

JBoss Enterprise Application Platform 4.3.0 EL4

SRPMS:
jboss-seam2-2.0.2.FP-1.ep1.24.el4.src.rpm
File outdated by:  RHBA-2013:1099
    MD5: 6940dd2689c3146fcf504541ef81c84d
SHA-256: a58cd06516d59dd79d264fd90450a5346cbf887ce8848f7fbdd5017c4003b1af
 
IA-32:
jboss-seam2-2.0.2.FP-1.ep1.24.el4.noarch.rpm
File outdated by:  RHBA-2013:1099
    MD5: 79a0ba189c031b7ea7e46a0f61c592f4
SHA-256: 46fdca2981a6116fc1e59a1e6b4c69c3e0c6e0f93fd8843b99db41c9c6c3a976
jboss-seam2-docs-2.0.2.FP-1.ep1.24.el4.noarch.rpm
File outdated by:  RHBA-2013:1099
    MD5: 9c01c4cc2b889c8063eff6d7ea8fc0c9
SHA-256: 18ba8685c97985dfeeff4a892c92eadb08f36fd27fe60b84ce340647f18c7e4f
 
x86_64:
jboss-seam2-2.0.2.FP-1.ep1.24.el4.noarch.rpm
File outdated by:  RHBA-2013:1099
    MD5: 79a0ba189c031b7ea7e46a0f61c592f4
SHA-256: 46fdca2981a6116fc1e59a1e6b4c69c3e0c6e0f93fd8843b99db41c9c6c3a976
jboss-seam2-docs-2.0.2.FP-1.ep1.24.el4.noarch.rpm
File outdated by:  RHBA-2013:1099
    MD5: 9c01c4cc2b889c8063eff6d7ea8fc0c9
SHA-256: 18ba8685c97985dfeeff4a892c92eadb08f36fd27fe60b84ce340647f18c7e4f
 
JBoss Enterprise Application Platform 4.3.0 EL5

SRPMS:
jboss-seam2-2.0.2.FP-1.ep1.24.el5.src.rpm
File outdated by:  RHBA-2013:1099
    MD5: 85bb7fe6d9502959712e6493fabffc77
SHA-256: 058de117baef1c5bef0ebc2dfdecc7bc140effdd516e10337beecef4af5f8dff
 
IA-32:
jboss-seam2-2.0.2.FP-1.ep1.24.el5.noarch.rpm
File outdated by:  RHBA-2013:1099
    MD5: 1a45a61175e402f49ca0b1cd866f477c
SHA-256: a0cb3226d7bf94fe6249011e072b3b563f6a72b9e0acf748a9c43f6a36ea6bf5
jboss-seam2-docs-2.0.2.FP-1.ep1.24.el5.noarch.rpm
File outdated by:  RHBA-2013:1099
    MD5: 96c60acf421a0a5563b2b66a22576f95
SHA-256: e56cf1c7b66d9b7b2149b09dbb30a0699b3801846ce82173c9b4d1aacf0cac30
 
x86_64:
jboss-seam2-2.0.2.FP-1.ep1.24.el5.noarch.rpm
File outdated by:  RHBA-2013:1099
    MD5: 1a45a61175e402f49ca0b1cd866f477c
SHA-256: a0cb3226d7bf94fe6249011e072b3b563f6a72b9e0acf748a9c43f6a36ea6bf5
jboss-seam2-docs-2.0.2.FP-1.ep1.24.el5.noarch.rpm
File outdated by:  RHBA-2013:1099
    MD5: 96c60acf421a0a5563b2b66a22576f95
SHA-256: e56cf1c7b66d9b7b2149b09dbb30a0699b3801846ce82173c9b4d1aacf0cac30
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

615956 - CVE-2010-1871 JBoss Seam / Seam2: Improper sanitization of parametrized JBoss EL expressions (ACE)


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/