RHSA-2017:0829: Important: jboss-ec2-eap security, bug fix, and enhancement update
The jboss-ec2-eap packages provide scripts for Red Hat JBoss Enterprise Application Platform running on the Amazon Web Services (AWS) Elastic Compute Cloud (EC2).With this update, the jboss-ec2-eap package has been updated to ensure compatibility with Red Hat JBoss Enterprise Application Platform 6.4.14.Security Fix(es): It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d init scripts (i.e. on Red Hat Enterprise Linux 6 and earlier), the file is sourced by the jboss init script and its content executed with root privileges when jboss service is started, stopped, or restarted. (CVE-2016-8657) It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. (CVE-2017-6056) It was found that GZIPInterceptor is enabled when not necessarily required in RESTEasy. An attacker could use this flaw to launch a Denial of Service attack. (CVE-2016-6346) Red Hat would like to thank Mikhail Egorov (Odin) for reporting theCVE-2016-6346 issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:0829?
The severity of RHSA-2017:0829 is classified as moderate.
How do I fix RHSA-2017:0829?
To fix RHSA-2017:0829, you should update the jboss-ec2-eap package to version 7.5.14-2.Final_redhat_2.ep6.el6.
What are the affected software versions for RHSA-2017:0829?
The affected software versions for RHSA-2017:0829 include jboss-ec2-eap and jboss-ec2-eap-samples up to 7.5.14-2.Final_redhat_2.ep6.el6.
Is RHSA-2017:0829 related to Red Hat JBoss Enterprise Application Platform?
Yes, RHSA-2017:0829 specifically addresses issues in the jboss-ec2-eap packages used in Red Hat JBoss Enterprise Application Platform.
What platforms does RHSA-2017:0829 affect?
RHSA-2017:0829 affects the el6 platform.