Skip to navigation

Security Advisory Moderate: axis security update

Advisory: RHSA-2013:0269-1
Type: Security Advisory
Severity: Moderate
Issued on: 2013-02-19
Last updated on: 2013-02-19
Affected Products: Red Hat Enterprise Linux Desktop (v. 6)
Red Hat Enterprise Linux HPC Node (v. 6)
Red Hat Enterprise Linux Server (v. 6)
Red Hat Enterprise Linux Server EUS (v. 6.3.z)
Red Hat Enterprise Linux Workstation (v. 6)
CVEs (cve.mitre.org): CVE-2012-5784

Details

Updated axis packages that fix one security issue are now available for Red
Hat Enterprise Linux 6.

The Red Hat Security Response Team has rated this update as having moderate
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.

Apache Axis is an implementation of SOAP (Simple Object Access Protocol).
It can be used to build both web service clients and servers.

Apache Axis did not verify that the server hostname matched the domain name
in the subject's Common Name (CN) or subjectAltName field in X.509
certificates. This could allow a man-in-the-middle attacker to spoof an SSL
server if they had a certificate that was valid for any domain name.
(CVE-2012-5784)

All users of axis are advised to upgrade to these updated packages, which
correct this issue. Applications using Apache Axis must be restarted for
this update to take effect.


Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258

Updated packages

Red Hat Enterprise Linux Desktop (v. 6)

SRPMS:
axis-1.2.1-7.3.el6_3.src.rpm     MD5: 5718e5b975af86f275308e85b2e96f0c
SHA-256: 514ae0a4d44d2adc1f401399590f781121e1e051cf2ed7089c640a0f536f8298
 
IA-32:
axis-1.2.1-7.3.el6_3.noarch.rpm     MD5: 6b01617b34e15a54c7720c9c8dac0bea
SHA-256: fa4e22a1d6914791fcef7c03c93fc31e829dbff8ab15554a4679500dde6e7a45
axis-javadoc-1.2.1-7.3.el6_3.noarch.rpm     MD5: 79d0746586e12309cf718a0c7421316f
SHA-256: d39477325960d758de3706eca80c571a25ad974b7c6f28ce7e3a3140b0ef8766
axis-manual-1.2.1-7.3.el6_3.noarch.rpm     MD5: f8fb5e2678fb9c9c29d1d45320317e88
SHA-256: ebffae7463ace5c1f92f0821e09097631ea4d48277aaddb92ab25961c5bbe020
 
x86_64:
axis-1.2.1-7.3.el6_3.noarch.rpm     MD5: 6b01617b34e15a54c7720c9c8dac0bea
SHA-256: fa4e22a1d6914791fcef7c03c93fc31e829dbff8ab15554a4679500dde6e7a45
axis-javadoc-1.2.1-7.3.el6_3.noarch.rpm     MD5: 79d0746586e12309cf718a0c7421316f
SHA-256: d39477325960d758de3706eca80c571a25ad974b7c6f28ce7e3a3140b0ef8766
axis-manual-1.2.1-7.3.el6_3.noarch.rpm     MD5: f8fb5e2678fb9c9c29d1d45320317e88
SHA-256: ebffae7463ace5c1f92f0821e09097631ea4d48277aaddb92ab25961c5bbe020
 
Red Hat Enterprise Linux HPC Node (v. 6)

SRPMS:
axis-1.2.1-7.3.el6_3.src.rpm     MD5: 5718e5b975af86f275308e85b2e96f0c
SHA-256: 514ae0a4d44d2adc1f401399590f781121e1e051cf2ed7089c640a0f536f8298
 
x86_64:
axis-1.2.1-7.3.el6_3.noarch.rpm     MD5: 6b01617b34e15a54c7720c9c8dac0bea
SHA-256: fa4e22a1d6914791fcef7c03c93fc31e829dbff8ab15554a4679500dde6e7a45
axis-javadoc-1.2.1-7.3.el6_3.noarch.rpm     MD5: 79d0746586e12309cf718a0c7421316f
SHA-256: d39477325960d758de3706eca80c571a25ad974b7c6f28ce7e3a3140b0ef8766
axis-manual-1.2.1-7.3.el6_3.noarch.rpm     MD5: f8fb5e2678fb9c9c29d1d45320317e88
SHA-256: ebffae7463ace5c1f92f0821e09097631ea4d48277aaddb92ab25961c5bbe020
 
Red Hat Enterprise Linux Server (v. 6)

SRPMS:
axis-1.2.1-7.3.el6_3.src.rpm     MD5: 5718e5b975af86f275308e85b2e96f0c
SHA-256: 514ae0a4d44d2adc1f401399590f781121e1e051cf2ed7089c640a0f536f8298
 
IA-32:
axis-1.2.1-7.3.el6_3.noarch.rpm     MD5: 6b01617b34e15a54c7720c9c8dac0bea
SHA-256: fa4e22a1d6914791fcef7c03c93fc31e829dbff8ab15554a4679500dde6e7a45
axis-javadoc-1.2.1-7.3.el6_3.noarch.rpm     MD5: 79d0746586e12309cf718a0c7421316f
SHA-256: d39477325960d758de3706eca80c571a25ad974b7c6f28ce7e3a3140b0ef8766
axis-manual-1.2.1-7.3.el6_3.noarch.rpm     MD5: f8fb5e2678fb9c9c29d1d45320317e88
SHA-256: ebffae7463ace5c1f92f0821e09097631ea4d48277aaddb92ab25961c5bbe020
 
PPC:
axis-1.2.1-7.3.el6_3.noarch.rpm     MD5: 6b01617b34e15a54c7720c9c8dac0bea
SHA-256: fa4e22a1d6914791fcef7c03c93fc31e829dbff8ab15554a4679500dde6e7a45
axis-javadoc-1.2.1-7.3.el6_3.noarch.rpm     MD5: 79d0746586e12309cf718a0c7421316f
SHA-256: d39477325960d758de3706eca80c571a25ad974b7c6f28ce7e3a3140b0ef8766
axis-manual-1.2.1-7.3.el6_3.noarch.rpm     MD5: f8fb5e2678fb9c9c29d1d45320317e88
SHA-256: ebffae7463ace5c1f92f0821e09097631ea4d48277aaddb92ab25961c5bbe020
 
s390x:
axis-1.2.1-7.3.el6_3.noarch.rpm     MD5: 6b01617b34e15a54c7720c9c8dac0bea
SHA-256: fa4e22a1d6914791fcef7c03c93fc31e829dbff8ab15554a4679500dde6e7a45
axis-javadoc-1.2.1-7.3.el6_3.noarch.rpm     MD5: 79d0746586e12309cf718a0c7421316f
SHA-256: d39477325960d758de3706eca80c571a25ad974b7c6f28ce7e3a3140b0ef8766
axis-manual-1.2.1-7.3.el6_3.noarch.rpm     MD5: f8fb5e2678fb9c9c29d1d45320317e88
SHA-256: ebffae7463ace5c1f92f0821e09097631ea4d48277aaddb92ab25961c5bbe020
 
x86_64:
axis-1.2.1-7.3.el6_3.noarch.rpm     MD5: 6b01617b34e15a54c7720c9c8dac0bea
SHA-256: fa4e22a1d6914791fcef7c03c93fc31e829dbff8ab15554a4679500dde6e7a45
axis-javadoc-1.2.1-7.3.el6_3.noarch.rpm     MD5: 79d0746586e12309cf718a0c7421316f
SHA-256: d39477325960d758de3706eca80c571a25ad974b7c6f28ce7e3a3140b0ef8766
axis-manual-1.2.1-7.3.el6_3.noarch.rpm     MD5: f8fb5e2678fb9c9c29d1d45320317e88
SHA-256: ebffae7463ace5c1f92f0821e09097631ea4d48277aaddb92ab25961c5bbe020
 
Red Hat Enterprise Linux Server EUS (v. 6.3.z)

SRPMS:
axis-1.2.1-7.3.el6_3.src.rpm     MD5: 5718e5b975af86f275308e85b2e96f0c
SHA-256: 514ae0a4d44d2adc1f401399590f781121e1e051cf2ed7089c640a0f536f8298
 
IA-32:
axis-1.2.1-7.3.el6_3.noarch.rpm     MD5: 6b01617b34e15a54c7720c9c8dac0bea
SHA-256: fa4e22a1d6914791fcef7c03c93fc31e829dbff8ab15554a4679500dde6e7a45
axis-javadoc-1.2.1-7.3.el6_3.noarch.rpm     MD5: 79d0746586e12309cf718a0c7421316f
SHA-256: d39477325960d758de3706eca80c571a25ad974b7c6f28ce7e3a3140b0ef8766
axis-manual-1.2.1-7.3.el6_3.noarch.rpm     MD5: f8fb5e2678fb9c9c29d1d45320317e88
SHA-256: ebffae7463ace5c1f92f0821e09097631ea4d48277aaddb92ab25961c5bbe020
 
PPC:
axis-1.2.1-7.3.el6_3.noarch.rpm     MD5: 6b01617b34e15a54c7720c9c8dac0bea
SHA-256: fa4e22a1d6914791fcef7c03c93fc31e829dbff8ab15554a4679500dde6e7a45
axis-javadoc-1.2.1-7.3.el6_3.noarch.rpm     MD5: 79d0746586e12309cf718a0c7421316f
SHA-256: d39477325960d758de3706eca80c571a25ad974b7c6f28ce7e3a3140b0ef8766
axis-manual-1.2.1-7.3.el6_3.noarch.rpm     MD5: f8fb5e2678fb9c9c29d1d45320317e88
SHA-256: ebffae7463ace5c1f92f0821e09097631ea4d48277aaddb92ab25961c5bbe020
 
s390x:
axis-1.2.1-7.3.el6_3.noarch.rpm     MD5: 6b01617b34e15a54c7720c9c8dac0bea
SHA-256: fa4e22a1d6914791fcef7c03c93fc31e829dbff8ab15554a4679500dde6e7a45
axis-javadoc-1.2.1-7.3.el6_3.noarch.rpm     MD5: 79d0746586e12309cf718a0c7421316f
SHA-256: d39477325960d758de3706eca80c571a25ad974b7c6f28ce7e3a3140b0ef8766
axis-manual-1.2.1-7.3.el6_3.noarch.rpm     MD5: f8fb5e2678fb9c9c29d1d45320317e88
SHA-256: ebffae7463ace5c1f92f0821e09097631ea4d48277aaddb92ab25961c5bbe020
 
x86_64:
axis-1.2.1-7.3.el6_3.noarch.rpm     MD5: 6b01617b34e15a54c7720c9c8dac0bea
SHA-256: fa4e22a1d6914791fcef7c03c93fc31e829dbff8ab15554a4679500dde6e7a45
axis-javadoc-1.2.1-7.3.el6_3.noarch.rpm     MD5: 79d0746586e12309cf718a0c7421316f
SHA-256: d39477325960d758de3706eca80c571a25ad974b7c6f28ce7e3a3140b0ef8766
axis-manual-1.2.1-7.3.el6_3.noarch.rpm     MD5: f8fb5e2678fb9c9c29d1d45320317e88
SHA-256: ebffae7463ace5c1f92f0821e09097631ea4d48277aaddb92ab25961c5bbe020
 
Red Hat Enterprise Linux Workstation (v. 6)

SRPMS:
axis-1.2.1-7.3.el6_3.src.rpm     MD5: 5718e5b975af86f275308e85b2e96f0c
SHA-256: 514ae0a4d44d2adc1f401399590f781121e1e051cf2ed7089c640a0f536f8298
 
IA-32:
axis-1.2.1-7.3.el6_3.noarch.rpm     MD5: 6b01617b34e15a54c7720c9c8dac0bea
SHA-256: fa4e22a1d6914791fcef7c03c93fc31e829dbff8ab15554a4679500dde6e7a45
axis-javadoc-1.2.1-7.3.el6_3.noarch.rpm     MD5: 79d0746586e12309cf718a0c7421316f
SHA-256: d39477325960d758de3706eca80c571a25ad974b7c6f28ce7e3a3140b0ef8766
axis-manual-1.2.1-7.3.el6_3.noarch.rpm     MD5: f8fb5e2678fb9c9c29d1d45320317e88
SHA-256: ebffae7463ace5c1f92f0821e09097631ea4d48277aaddb92ab25961c5bbe020
 
x86_64:
axis-1.2.1-7.3.el6_3.noarch.rpm     MD5: 6b01617b34e15a54c7720c9c8dac0bea
SHA-256: fa4e22a1d6914791fcef7c03c93fc31e829dbff8ab15554a4679500dde6e7a45
axis-javadoc-1.2.1-7.3.el6_3.noarch.rpm     MD5: 79d0746586e12309cf718a0c7421316f
SHA-256: d39477325960d758de3706eca80c571a25ad974b7c6f28ce7e3a3140b0ef8766
axis-manual-1.2.1-7.3.el6_3.noarch.rpm     MD5: f8fb5e2678fb9c9c29d1d45320317e88
SHA-256: ebffae7463ace5c1f92f0821e09097631ea4d48277aaddb92ab25961c5bbe020
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

873252 - CVE-2012-5784 axis: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/