Skip to navigation

Security Advisory Moderate: jasperreports-server-pro security and bug fix update

Advisory: RHSA-2012:1537-1
Type: Security Advisory
Severity: Moderate
Issued on: 2012-12-04
Last updated on: 2012-12-04
Affected Products: Red Hat Enterprise Virtualization 3
Red Hat Enterprise Virtualization 3.1
CVEs (cve.mitre.org): CVE-2009-2625

Details

An updated jasperreports-server-pro package that fixes one security issue
and various bugs is now available.

The Red Hat Security Response Team has rated this update as having moderate
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.

JasperReports Server is a reporting server.

A flaw was found in the way the Apache Xerces2 Java Parser processed the
SYSTEM identifier in DTDs. A remote attacker could provide a
specially-crafted XML file, which once parsed by an application using the
Apache Xerces2 Java Parser, would lead to a denial of service (application
hang due to excessive CPU use). (CVE-2009-2625)

This update also fixes the following bugs:

* Adding a user to any ROLE caused an unexpected exception. (BZ#730712)

* Previously, the jasperreports-server-pro RPM spec file contained the
"%{dist}" tag on the "Release" line. To comply with the packaging and
naming guidelines, the tag has been changed to "%{?dist}" with this update.
(BZ#868927)

* In some cases reports were opened with an incorrect list of
Entity/Entities. (BZ#842687)

Note: The jasperreports-server-pro package replaces rhevm-reports-server
from Red Hat Enterprise Virtualization Manager 3.0.

Users are advised to upgrade to this updated package, which corrects these
issues.


Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258

Updated packages

Red Hat Enterprise Virtualization 3

SRPMS:
jasperreports-server-pro-4.7.1-2.el6ev.src.rpm     MD5: 5422c4542a5440bcb5aa45dd1cb3a76a
SHA-256: c06aa2f8d7174f6271a44c4c84cc9d0f1833a117d7ddb45e9c1634b132a8f523
 
x86_64:
jasperreports-server-pro-4.7.1-2.el6ev.noarch.rpm     MD5: 9f74e467572eda6d13de24920bd655a1
SHA-256: bb8300bb36c72b171a679dee2fc614f70cb8ca71e03f956e02d89c0c3196e751
 
Red Hat Enterprise Virtualization 3.1

SRPMS:
jasperreports-server-pro-4.7.1-2.el6ev.src.rpm     MD5: 5422c4542a5440bcb5aa45dd1cb3a76a
SHA-256: c06aa2f8d7174f6271a44c4c84cc9d0f1833a117d7ddb45e9c1634b132a8f523
 
x86_64:
jasperreports-server-pro-4.7.1-2.el6ev.noarch.rpm     MD5: 9f74e467572eda6d13de24920bd655a1
SHA-256: bb8300bb36c72b171a679dee2fc614f70cb8ca71e03f956e02d89c0c3196e751
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

512921 - CVE-2009-2625 xerces-j2, JDK: XML parsing Denial-Of-Service (6845701)
842687 - [rhevm-reports] - Webadmin - Display incorrect selection in Report (When using Reports via Webadmin)


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/