RHSA-2010:0119: Low: JBoss Enterprise Web Server 1.0.1 update

Published Feb 23, 2010
·
Updated

JBoss Enterprise Web Server is a fully integrated and certified setof components for hosting Java web applications. It is comprised of theindustry's leading web server (Apache HTTP Server), the popular ApacheTomcat servlet container, as well as the modjk connector and the TomcatNative library.This 1.0.1 release of JBoss Enterprise Web Server serves as a replacementto JBoss Enterprise Web Server 1.0.0 GA. These updated packages includea number of bug fixes. For detailed component, installation, and bug fixinformation, refer to the JBoss Enterprise Web Server 1.0.1 Release Notes,available shortly from the link in the References section of this erratum.The following security issues are also fixed with this release:A directory traversal flaw was found in the Tomcat deployment process. Anattacker could create a specially-crafted WAR file, which once deployedby a local, unsuspecting user, would lead to attacker-controlled contentbeing deployed outside of the web root, into directories accessible to theTomcat process. (CVE-2009-2693)A second directory traversal flaw was found in the Tomcat deploymentprocess. WAR file names were not sanitized, which could allow an attackerto create a specially-crafted WAR file that could delete files in theTomcat host's work directory. (CVE-2009-2902)A flaw was found in the way the TLS/SSL (Transport Layer Security/SecureSockets Layer) protocols handle session renegotiation. A man-in-the-middleattacker could use this flaw to prefix arbitrary plain text to a client'ssession (for example, an HTTPS connection to a website). This could forcethe server to process an attacker's request as if authenticated using thevictim's credentials. (CVE-2009-3555)This update provides a mitigation for this flaw in the followingcomponents:tomcat5 and tomcat6: A new attribute, allowUnsafeLegacyRenegotiation, isavailable for the blocking IO (BIO) connector using JSSE, to enable ordisable TLS session renegotiation. The default value is "false", meaningsession renegotiation, both client- and server-initiated, is disabled bydefault.tomcat-native: Client-initiated renegotiation is now rejected by the nativeconnector. Server-initiated renegotiation is still allowed.Refer to the following Knowledgebase article for additional details aboutthe CVE-2009-3555 flaw: http://kbase.redhat.com/faq/docs/DOC-20491 All users of JBoss Enterprise Web Server 1.0.0 on Red Hat Enterprise Linux4 and 5 are advised to upgrade to these updated packages.

Affected Software

43 affected componentsFixes available
redhat/glassfish-jsf<1.2_13-3.ep5.el5
1.2_13-3.ep5.el5
redhat/httpd<2.2.14-1.2.1.ep5.el5
2.2.14-1.2.1.ep5.el5
redhat/jakarta-commons-chain<1.2-2.1.1.ep5.el5
1.2-2.1.1.ep5.el5
redhat/jakarta-commons-io<1.4-1.1.ep5.el5
1.4-1.1.ep5.el5
redhat/jakarta-oro<2.0.8-3.1.ep5.el5
2.0.8-3.1.ep5.el5
redhat/struts12<1.2.9-2.ep5.el5
1.2.9-2.ep5.el5
redhat/tomcat-native<1.1.19-2.0.1.ep5.el5
1.1.19-2.0.1.ep5.el5
redhat/tomcat5<5.5.28-7.1.ep5.el5
5.5.28-7.1.ep5.el5
redhat/tomcat6<6.0.24-2.1.ep5.el5
6.0.24-2.1.ep5.el5
redhat/glassfish-jsf<1.2_13-3.ep5.el5
1.2_13-3.ep5.el5
redhat/httpd<2.2.14-1.2.1.ep5.el5
2.2.14-1.2.1.ep5.el5
redhat/httpd-devel<2.2.14-1.2.1.ep5.el5
2.2.14-1.2.1.ep5.el5
redhat/httpd-manual<2.2.14-1.2.1.ep5.el5
2.2.14-1.2.1.ep5.el5
redhat/jakarta-commons-chain<1.2-2.1.1.ep5.el5
1.2-2.1.1.ep5.el5
redhat/jakarta-commons-io<1.4-1.1.ep5.el5
1.4-1.1.ep5.el5
redhat/jakarta-oro<2.0.8-3.1.ep5.el5
2.0.8-3.1.ep5.el5
redhat/struts12<1.2.9-2.ep5.el5
1.2.9-2.ep5.el5
redhat/tomcat-native<1.1.19-2.0.1.ep5.el5
1.1.19-2.0.1.ep5.el5
redhat/tomcat5<5.5.28-7.1.ep5.el5
5.5.28-7.1.ep5.el5
redhat/tomcat5-admin-webapps<5.5.28-7.1.ep5.el5
5.5.28-7.1.ep5.el5
redhat/tomcat5-common-lib<5.5.28-7.1.ep5.el5
5.5.28-7.1.ep5.el5
redhat/tomcat5-jasper<5.5.28-7.1.ep5.el5
5.5.28-7.1.ep5.el5
redhat/tomcat5-jasper-eclipse<5.5.28-7.1.ep5.el5
5.5.28-7.1.ep5.el5
redhat/tomcat5-jasper-javadoc<5.5.28-7.1.ep5.el5
5.5.28-7.1.ep5.el5
redhat/tomcat5-jsp<2.0-api-5.5.28-7.1.ep5.el5
2.0-api-5.5.28-7.1.ep5.el5
redhat/tomcat5-jsp<2.0-api-javadoc-5.5.28-7.1.ep5.el5
2.0-api-javadoc-5.5.28-7.1.ep5.el5
redhat/tomcat5-parent<5.5.28-7.1.ep5.el5
5.5.28-7.1.ep5.el5
redhat/tomcat5-server-lib<5.5.28-7.1.ep5.el5
5.5.28-7.1.ep5.el5
redhat/tomcat5-servlet<2.4-api-5.5.28-7.1.ep5.el5
2.4-api-5.5.28-7.1.ep5.el5
redhat/tomcat5-servlet<2.4-api-javadoc-5.5.28-7.1.ep5.el5
2.4-api-javadoc-5.5.28-7.1.ep5.el5
redhat/tomcat5-webapps<5.5.28-7.1.ep5.el5
5.5.28-7.1.ep5.el5
redhat/tomcat6<6.0.24-2.1.ep5.el5
6.0.24-2.1.ep5.el5
redhat/tomcat6-admin-webapps<6.0.24-2.1.ep5.el5
6.0.24-2.1.ep5.el5
redhat/tomcat6-docs-webapp<6.0.24-2.1.ep5.el5
6.0.24-2.1.ep5.el5
redhat/tomcat6-el<1.0-api-6.0.24-2.1.ep5.el5
1.0-api-6.0.24-2.1.ep5.el5
redhat/tomcat6-javadoc<6.0.24-2.1.ep5.el5
6.0.24-2.1.ep5.el5
redhat/tomcat6-jsp<2.1-api-6.0.24-2.1.ep5.el5
2.1-api-6.0.24-2.1.ep5.el5
redhat/tomcat6-lib<6.0.24-2.1.ep5.el5
6.0.24-2.1.ep5.el5
redhat/tomcat6-log4j<6.0.24-2.1.ep5.el5
6.0.24-2.1.ep5.el5
redhat/tomcat6-servlet<2.5-api-6.0.24-2.1.ep5.el5
2.5-api-6.0.24-2.1.ep5.el5
redhat/tomcat6-webapps<6.0.24-2.1.ep5.el5
6.0.24-2.1.ep5.el5
redhat/httpd-devel<2.2.14-1.2.1.ep5.el5
2.2.14-1.2.1.ep5.el5
redhat/httpd-manual<2.2.14-1.2.1.ep5.el5
2.2.14-1.2.1.ep5.el5

Remediation

Event History

Feb 23, 2010
Advisory Published
via Red Hat·12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2010:0119?

The severity of RHSA-2010:0119 is critical due to disclosed vulnerabilities in the affected software components.

2

How do I fix RHSA-2010:0119?

To fix RHSA-2010:0119, update the affected packages to their recommended versions as provided in the advisory.

3

What software is affected by RHSA-2010:0119?

RHSA-2010:0119 affects several packages including JBoss Enterprise Web Server components among others.

4

What vulnerabilities are addressed in RHSA-2010:0119?

RHSA-2010:0119 addresses multiple vulnerabilities that could lead to remote code execution and denial of service.

5

When was RHSA-2010:0119 released?

RHSA-2010:0119 was released by Red Hat on March 1, 2010.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203