- Issued:
- 2010-12-08
- Updated:
- 2010-12-08
RHSA-2010:0964 - Security Advisory
Synopsis
Low: jboss-remoting security update
Type/Severity
Security Advisory: Low
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
An updated jboss-remoting package that fixes one security issue is now
available for JBoss Enterprise Application Platform 4.3 for Red Hat
Enterprise Linux 4 and 5.
The Red Hat Security Response Team has rated this update as having low
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.
Description
JBoss Remoting is a framework for building distributed applications in
Java.
The JBoss Enterprise Application Platform 4.3.0.CP09 updates RHSA-2010:0937
and RHSA-2010:0938 did not, unlike the errata texts stated, provide a fix
for CVE-2010-3862. A remote attacker could use specially-crafted input to
cause the JBoss Remoting listeners to become unresponsive, resulting in a
denial of service condition for services communicating via JBoss Remoting
sockets. (CVE-2010-4265)
Red Hat would like to thank Ole Husgaard of eXerp.com for reporting this
issue.
Warning: Before applying this update, backup your existing JBoss Enterprise
Application Platform installation (including all applications and
configuration files).
Users of JBoss Enterprise Application Platform 4.3 on Red Hat Enterprise
Linux 4 and 5 should upgrade to this updated package, which contains a
backported patch to correct this issue. The JBoss server process must be
restarted for this update to take effect.
Solution
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259
Affected Products
- JBoss Enterprise Application Platform 4.3.0 x86_64
- JBoss Enterprise Application Platform 4.3.0 i386
Fixes
- BZ - 660623 - CVE-2010-4265 jboss-remoting: missing fix for CVE-2010-3862
CVEs
JBoss Enterprise Application Platform 4.3.0
SRPM | |
---|---|
jboss-remoting-2.2.3-4.SP3.ep1.1.el5.src.rpm | SHA-256: cdd464467181b7ec423e05309bf15308337411cb05681ac518ae5b4d14184ce4 |
x86_64 | |
jboss-remoting-2.2.3-4.SP3.ep1.1.el5.noarch.rpm | SHA-256: a596027e852894757b59aa0cc97e532a12e0db5f38338a9273246159462e934c |
i386 | |
jboss-remoting-2.2.3-4.SP3.ep1.1.el5.noarch.rpm | SHA-256: a596027e852894757b59aa0cc97e532a12e0db5f38338a9273246159462e934c |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.