RHSA-2010:0119: Low: JBoss Enterprise Web Server 1.0.1 update
JBoss Enterprise Web Server is a fully integrated and certified setof components for hosting Java web applications. It is comprised of theindustry's leading web server (Apache HTTP Server), the popular ApacheTomcat servlet container, as well as the modjk connector and the TomcatNative library.This 1.0.1 release of JBoss Enterprise Web Server serves as a replacementto JBoss Enterprise Web Server 1.0.0 GA. These updated packages includea number of bug fixes. For detailed component, installation, and bug fixinformation, refer to the JBoss Enterprise Web Server 1.0.1 Release Notes,available shortly from the link in the References section of this erratum.The following security issues are also fixed with this release:A directory traversal flaw was found in the Tomcat deployment process. Anattacker could create a specially-crafted WAR file, which once deployedby a local, unsuspecting user, would lead to attacker-controlled contentbeing deployed outside of the web root, into directories accessible to theTomcat process. (CVE-2009-2693)A second directory traversal flaw was found in the Tomcat deploymentprocess. WAR file names were not sanitized, which could allow an attackerto create a specially-crafted WAR file that could delete files in theTomcat host's work directory. (CVE-2009-2902)A flaw was found in the way the TLS/SSL (Transport Layer Security/SecureSockets Layer) protocols handle session renegotiation. A man-in-the-middleattacker could use this flaw to prefix arbitrary plain text to a client'ssession (for example, an HTTPS connection to a website). This could forcethe server to process an attacker's request as if authenticated using thevictim's credentials. (CVE-2009-3555)This update provides a mitigation for this flaw in the followingcomponents:tomcat5 and tomcat6: A new attribute, allowUnsafeLegacyRenegotiation, isavailable for the blocking IO (BIO) connector using JSSE, to enable ordisable TLS session renegotiation. The default value is "false", meaningsession renegotiation, both client- and server-initiated, is disabled bydefault.tomcat-native: Client-initiated renegotiation is now rejected by the nativeconnector. Server-initiated renegotiation is still allowed.Refer to the following Knowledgebase article for additional details aboutthe CVE-2009-3555 flaw: http://kbase.redhat.com/faq/docs/DOC-20491 All users of JBoss Enterprise Web Server 1.0.0 on Red Hat Enterprise Linux4 and 5 are advised to upgrade to these updated packages.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0119?
The severity of RHSA-2010:0119 is critical due to disclosed vulnerabilities in the affected software components.
How do I fix RHSA-2010:0119?
To fix RHSA-2010:0119, update the affected packages to their recommended versions as provided in the advisory.
What software is affected by RHSA-2010:0119?
RHSA-2010:0119 affects several packages including JBoss Enterprise Web Server components among others.
What vulnerabilities are addressed in RHSA-2010:0119?
RHSA-2010:0119 addresses multiple vulnerabilities that could lead to remote code execution and denial of service.
When was RHSA-2010:0119 released?
RHSA-2010:0119 was released by Red Hat on March 1, 2010.