exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Red Hat Security Advisory 2012-0036-01

Red Hat Security Advisory 2012-0036-01
Posted Jan 18, 2012
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2012-0036-01 - The mod_cluster native component provides a native build of mod_cluster for the Apache HTTP Server. mod_cluster is an httpd-based load balancer. Like mod_jk, it uses a communication channel to forward requests from httpd to an application server node. It was found that mod_cluster allowed worker nodes to register on any virtual host, regardless of the security constraints applied to other vhosts. In a typical environment, there will be one vhost configured internally for worker nodes, and another configured externally for serving content. A remote attacker could use this flaw to register an attacker-controlled worker node via an external vhost that is not configured to apply security constraints, then use that worker node to serve malicious content, intercept credentials, and hijack user sessions.

tags | advisory, remote, web
systems | linux, redhat
advisories | CVE-2011-4608
SHA-256 | 2650ae52c3e34a3a7a3098090b937e54eb9c4cd8948b9b0ba0513ff5be2d368a

Red Hat Security Advisory 2012-0036-01

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
Red Hat Security Advisory

Synopsis: Important: mod_cluster-native security update
Advisory ID: RHSA-2012:0036-01
Product: JBoss Enterprise Web Server
Advisory URL: https://rhn.redhat.com/errata/RHSA-2012-0036.html
Issue date: 2012-01-18
CVE Names: CVE-2011-4608
=====================================================================

1. Summary:

An update for the mod_cluster native component for JBoss Enterprise Web
Server 1.0.2 that fixes one security issue is now available from the Red
Hat Customer Portal.

The Red Hat Security Response Team has rated this update as having
important security impact. A Common Vulnerability Scoring System (CVSS)
base score, which gives a detailed severity rating, is available from the
CVE link in the References section.

2. Description:

The mod_cluster native component provides a native build of mod_cluster for
the Apache HTTP Server (httpd). mod_cluster is an httpd-based load
balancer. Like mod_jk, it uses a communication channel to forward requests
from httpd to an application server node.

It was found that mod_cluster allowed worker nodes to register on any
virtual host (vhost), regardless of the security constraints applied to
other vhosts. In a typical environment, there will be one vhost configured
internally for worker nodes, and another configured externally for serving
content. A remote attacker could use this flaw to register an
attacker-controlled worker node via an external vhost that is not
configured to apply security constraints, then use that worker node to
serve malicious content, intercept credentials, and hijack user sessions.
(CVE-2011-4608)

This update also upgrades mod_cluster to version 1.0.10.GA_CP02.

All users of JBoss Enterprise Web Server 1.0.2 as provided from the Red
Hat Customer Portal are advised to apply this update.

3. Solution:

The References section of this erratum contains a download link (you must
log in to download the update).

The Apache HTTP Server must be restarted for this update to take effect.

4. Bugs fixed (http://bugzilla.redhat.com/):

767020 - CVE-2011-4608 mod_cluster: malicious worker nodes can register on any vhost

5. References:

https://www.redhat.com/security/data/cve/CVE-2011-4608.html
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=webserver&downloadType=securityPatches&version=1.0.2

6. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2012 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFPFx4BXlSAg2UNWIIRApFVAJ9o4z6OxY3g3Tkte04TWWY6Tg9tIACaA1HT
FbBGKAF7h0Pil2GXRy7Y7mI=
=gUNC
-----END PGP SIGNATURE-----


--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close