RHSA-2017:3115: Moderate: Red Hat JBoss Fuse/A-MQ 6.3 R5 security and bug fix update
Red Hat JBoss Fuse, based on Apache ServiceMix, provides a small-footprint, flexible, open source enterprise service bus and integration platform. Red Hat JBoss A-MQ, based on Apache ActiveMQ, is a standards compliant messaging system that is tailored for use in mission critical applications.<br>This patch is an update to Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. It includes bug fixes and enhancements, which are documented in the readme.txt file included with the patch files.<br>Security Fix(es):<br><li> It was found that ResourceServlet in Spring Framework does not sanitize the paths that have been provided properly. An attacker can utilize this flaw to conduct directory traversal attacks. (CVE-2016-9878)</li> <li> A vulnerability was discovered in Apache Thrift client libraries that allows remote, authenticated attackers to cause an infinite recursion via vectors involving the skip function, resulting in a denial of service (DoS) condition. (CVE-2015-3254)</li> <li> A vulnerability was discovered in JSch that allows a malicious sftp server to force a client-side relative path traversal in jsch's implementation for recursive sftp-get. An attacker could leverage this to write files outside the client's download basedir with effective permissions of the jsch sftp client process. (CVE-2016-5725)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:3115?
The severity of RHSA-2017:3115 is classified as moderate.
How do I fix RHSA-2017:3115?
To fix RHSA-2017:3115, update Red Hat JBoss Fuse and Red Hat A-MQ to the latest available versions.
What versions of Red Hat JBoss Fuse and Red Hat A-MQ are affected by RHSA-2017:3115?
RHSA-2017:3115 affects unspecified versions of Red Hat JBoss Fuse and Red Hat A-MQ.
Are there any workarounds for RHSA-2017:3115?
No specific workarounds for RHSA-2017:3115 have been provided.
What kind of vulnerabilities does RHSA-2017:3115 address?
RHSA-2017:3115 addresses vulnerabilities related to security issues in Red Hat JBoss Fuse and Red Hat A-MQ.