Skip to navigation

Security Advisory Low: sblim-cim-client2 security update

Advisory: RHSA-2012:0987-4
Type: Security Advisory
Severity: Low
Issued on: 2012-06-20
Last updated on: 2012-06-20
Affected Products: Red Hat Enterprise Linux Server (v. 6)
Red Hat Enterprise Linux Workstation (v. 6)
CVEs (cve.mitre.org): CVE-2012-2328

Details

Updated sblim-cim-client2 packages that fix one security issue are now
available for Red Hat Enterprise Linux 6.

The Red Hat Security Response Team has rated this update as having low
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.

The SBLIM (Standards-Based Linux Instrumentation for Manageability) CIM
(Common Information Model) Client is a class library for Java applications
that provides access to CIM servers using the CIM Operations over HTTP
protocol defined by the DMTF (Distributed Management Task Force) standards.

It was found that the Java HashMap implementation was susceptible to
predictable hash collisions. SBLIM uses HashMap when parsing XML inputs. A
specially-crafted CIM-XML message from a WBEM (Web-Based Enterprise
Management) server could cause a SBLIM client to use an excessive amount of
CPU. Randomization has been added to help avoid collisions. (CVE-2012-2328)

All users of sblim-cim-client2 are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue.


Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258

Updated packages

Red Hat Enterprise Linux Server (v. 6)

SRPMS:
sblim-cim-client2-2.1.3-2.el6.src.rpm     MD5: 3d501f1c20fd736ab9a2c6f154f5981b
SHA-256: 6e95f33d30a4c246092d08a700b1fd8396bfbb02c7f952837e0398b749d3ea37
 
IA-32:
sblim-cim-client2-2.1.3-2.el6.noarch.rpm     MD5: bb3c93c933b33c9adcb2872c7246262c
SHA-256: 9dbc6edc08307f346b38c683ae47710c9bb0b68ab6cdab5a2780355c12847ea2
sblim-cim-client2-javadoc-2.1.3-2.el6.noarch.rpm     MD5: fc883dd14e52b6d37f85ddca9c16b1c7
SHA-256: 68346c5058d065bc824ad8f3d0fbe1b93913b0dbe494491235fc6901ccb12239
sblim-cim-client2-manual-2.1.3-2.el6.noarch.rpm     MD5: 0601d1060434c5166ee571f540a8d356
SHA-256: c0e48eebd5a4d94c4d027c2852e0cfe9a883b3ffe350183b72394020b35600a5
 
PPC:
sblim-cim-client2-2.1.3-2.el6.noarch.rpm     MD5: bb3c93c933b33c9adcb2872c7246262c
SHA-256: 9dbc6edc08307f346b38c683ae47710c9bb0b68ab6cdab5a2780355c12847ea2
sblim-cim-client2-javadoc-2.1.3-2.el6.noarch.rpm     MD5: fc883dd14e52b6d37f85ddca9c16b1c7
SHA-256: 68346c5058d065bc824ad8f3d0fbe1b93913b0dbe494491235fc6901ccb12239
sblim-cim-client2-manual-2.1.3-2.el6.noarch.rpm     MD5: 0601d1060434c5166ee571f540a8d356
SHA-256: c0e48eebd5a4d94c4d027c2852e0cfe9a883b3ffe350183b72394020b35600a5
 
s390x:
sblim-cim-client2-2.1.3-2.el6.noarch.rpm     MD5: bb3c93c933b33c9adcb2872c7246262c
SHA-256: 9dbc6edc08307f346b38c683ae47710c9bb0b68ab6cdab5a2780355c12847ea2
sblim-cim-client2-javadoc-2.1.3-2.el6.noarch.rpm     MD5: fc883dd14e52b6d37f85ddca9c16b1c7
SHA-256: 68346c5058d065bc824ad8f3d0fbe1b93913b0dbe494491235fc6901ccb12239
sblim-cim-client2-manual-2.1.3-2.el6.noarch.rpm     MD5: 0601d1060434c5166ee571f540a8d356
SHA-256: c0e48eebd5a4d94c4d027c2852e0cfe9a883b3ffe350183b72394020b35600a5
 
x86_64:
sblim-cim-client2-2.1.3-2.el6.noarch.rpm     MD5: bb3c93c933b33c9adcb2872c7246262c
SHA-256: 9dbc6edc08307f346b38c683ae47710c9bb0b68ab6cdab5a2780355c12847ea2
sblim-cim-client2-javadoc-2.1.3-2.el6.noarch.rpm     MD5: fc883dd14e52b6d37f85ddca9c16b1c7
SHA-256: 68346c5058d065bc824ad8f3d0fbe1b93913b0dbe494491235fc6901ccb12239
sblim-cim-client2-manual-2.1.3-2.el6.noarch.rpm     MD5: 0601d1060434c5166ee571f540a8d356
SHA-256: c0e48eebd5a4d94c4d027c2852e0cfe9a883b3ffe350183b72394020b35600a5
 
Red Hat Enterprise Linux Workstation (v. 6)

SRPMS:
sblim-cim-client2-2.1.3-2.el6.src.rpm     MD5: 3d501f1c20fd736ab9a2c6f154f5981b
SHA-256: 6e95f33d30a4c246092d08a700b1fd8396bfbb02c7f952837e0398b749d3ea37
 
IA-32:
sblim-cim-client2-2.1.3-2.el6.noarch.rpm     MD5: bb3c93c933b33c9adcb2872c7246262c
SHA-256: 9dbc6edc08307f346b38c683ae47710c9bb0b68ab6cdab5a2780355c12847ea2
sblim-cim-client2-javadoc-2.1.3-2.el6.noarch.rpm     MD5: fc883dd14e52b6d37f85ddca9c16b1c7
SHA-256: 68346c5058d065bc824ad8f3d0fbe1b93913b0dbe494491235fc6901ccb12239
sblim-cim-client2-manual-2.1.3-2.el6.noarch.rpm     MD5: 0601d1060434c5166ee571f540a8d356
SHA-256: c0e48eebd5a4d94c4d027c2852e0cfe9a883b3ffe350183b72394020b35600a5
 
x86_64:
sblim-cim-client2-2.1.3-2.el6.noarch.rpm     MD5: bb3c93c933b33c9adcb2872c7246262c
SHA-256: 9dbc6edc08307f346b38c683ae47710c9bb0b68ab6cdab5a2780355c12847ea2
sblim-cim-client2-javadoc-2.1.3-2.el6.noarch.rpm     MD5: fc883dd14e52b6d37f85ddca9c16b1c7
SHA-256: 68346c5058d065bc824ad8f3d0fbe1b93913b0dbe494491235fc6901ccb12239
sblim-cim-client2-manual-2.1.3-2.el6.noarch.rpm     MD5: 0601d1060434c5166ee571f540a8d356
SHA-256: c0e48eebd5a4d94c4d027c2852e0cfe9a883b3ffe350183b72394020b35600a5
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

819733 - CVE-2012-2328 sblim: hash table collisions CPU usage DoS


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/