exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Red Hat Security Advisory 2018-2425-01

Red Hat Security Advisory 2018-2425-01
Posted Aug 15, 2018
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2018-2425-01 - Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on Wildfly. This release of Red Hat JBoss Enterprise Application Platform 7.1.4 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.1.3, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Issues addressed include denial of service and traversal vulnerabilities.

tags | advisory, java, denial of service, vulnerability
systems | linux, redhat
advisories | CVE-2017-12624, CVE-2018-1000180, CVE-2018-10237, CVE-2018-10862, CVE-2018-8039
SHA-256 | 2f4719608bc90a9d14acfdd78b23c0bce292db4871bea45d924d2b244d444ef2

Red Hat Security Advisory 2018-2425-01

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================
Red Hat Security Advisory

Synopsis: Important: Red Hat JBoss Enterprise Application Platform 7.1 security update
Advisory ID: RHSA-2018:2425-01
Product: Red Hat JBoss Enterprise Application Platform
Advisory URL: https://access.redhat.com/errata/RHSA-2018:2425
Issue date: 2018-08-15
CVE Names: CVE-2017-12624 CVE-2018-8039 CVE-2018-10237
CVE-2018-10862 CVE-2018-1000180
====================================================================
1. Summary:

A security update is now available for Red Hat JBoss Enterprise Application
Platform from the Customer Portal.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java
applications based on Wildfly.

This release of Red Hat JBoss Enterprise Application Platform 7.1.4 serves
as a replacement for Red Hat JBoss Enterprise Application Platform 7.1.3,
and includes bug fixes and enhancements, which are documented in the
Release Notes document linked to in the References.

Security Fix(es):

* guava: Unbounded memory allocation in AtomicDoubleArray and
CompoundOrdering classes allow remote attackers to cause a denial of
service (CVE-2018-10237)

* bouncycastle: flaw in the low-level interface to RSA key pair generator
(CVE-2018-1000180)

* cxf: Improper size validation in message attachment header for JAX-WS and
JAX-RS services (CVE-2017-12624)

* wildfly: wildfly-core: Path traversal can allow the extraction of .war
archives to write arbitrary files (CVE-2018-10862)

* cxf-core: apache-cxf: TLS hostname verification does not work correctly
with com.sun.net.ssl.* (CVE-2018-8039)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

3. Solution:

Before applying this update, back up your existing Red Hat JBoss Enterprise
Application Platform installation and deployed applications.

The References section of this erratum contains a download link (you must
log in to download the update).

The JBoss server process must be restarted for the update to take effect.

4. Bugs fixed (https://bugzilla.redhat.com/):

1515976 - CVE-2017-12624 cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services
1573391 - CVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service
1588306 - CVE-2018-1000180 bouncycastle: flaw in the low-level interface to RSA key pair generator
1593527 - CVE-2018-10862 wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip)
1595332 - CVE-2018-8039 apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.*

5. References:

https://access.redhat.com/security/cve/CVE-2017-12624
https://access.redhat.com/security/cve/CVE-2018-8039
https://access.redhat.com/security/cve/CVE-2018-10237
https://access.redhat.com/security/cve/CVE-2018-10862
https://access.redhat.com/security/cve/CVE-2018-1000180
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=7.1
https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/?version=7.1
https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.1/html-single/installation_guide/

6. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2018 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBW3QMo9zjgjWX9erEAQj3Jg//TJnDm3V4+FHEVu7+79sxaSoctBbJ5MrK
b7shp5A5rCfVGZKToa83p9O4Ztqq3taaeB4D+LyydP9cBca2ObtxF6hnLMzB3R5e
85AmrN0O+fEU2ZcU/v1MA4bXFcQx55hoE23GkLeRgkR/6i4Q3aJ/MVwCQmyZHVnU
eKbDl4tQSaKOvoVjsu1/ZXT3LbmtFnSOvI61R82BSzS0jpl4GN1XRY9cYZjZTVHy
0k6HnwFzeM02a+rN3ky2JtwYX7/y6CdU8ZRngV/zcoIUAzn+Msfp27Kpwcjz7tVT
rlvXNjOAPZrmbElJPKq5mggVgvTGtBiKL/tyWw97LZAMSttWLGA6bnVWynBQrPRm
7KCLJi2aUbrbOWeovSB+4tXy9KRA4ypJdk14GZ8TqLxJG8AJ21STr9U1KmwnXFFU
r6La2zut08vZtExH2fmBOv9bx6QyyUaRRxIYdQ69C5ON03y5pBD4M1ZgfefvOUY0
L7O1mgBK/75lAbkHTbADAz7VslrnBAM2j5MW+nVzEFrzy9vGhaA90OHbhj7Bj0S0
uamrhXRRJjvbVsourkovK5Vw9h8teQblHWcWnA8aiM3qdBNAu74DrhktKf4LB/4Y
PJdvw/Wm7GYB4RYM4aZx0XuGsf+Q+sXM1IavRcPGtYHBfPZrI6CIrPCTdMUIu3cd
nlDrWAd5pNc=glXl
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    28 Files
  • 16
    Jul 16th
    6 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close