| Summary: | resteasy new security issue CVE-2014-3490 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | herman.viaene, mageia, sysadmin-bugs |
| Version: | 4 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/607779/ | ||
| Whiteboard: | advisory MGA4-32-OK MGA4-64-OK | ||
| Source RPM: | resteasy-3.0.1-3.mga4.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2014-08-06 21:49:31 CEST
David Walser
2014-08-06 21:49:38 CEST
Whiteboard:
(none) =>
MGA4TOO, MGA3TOO Dropped from cauldron. Whiteboard:
MGA4TOO, MGA3TOO =>
(none) Probably on its way back to Cauldron, but it is fixed in SVN there. Patch checked into Mageia 4 SVN. Patched package uploaded for Mageia 4. Verifying that the updated packages install cleanly is sufficient for testing this update. Advisory: ======================== Updated resteasy packages fixes security vulnerability: It was found that the fix for CVE-2012-0818 was incomplete: external parameter entities were not disabled when the resteasy.document.expand.entity.references parameter was set to false. A remote attacker able to send XML requests to a RESTEasy endpoint could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks (CVE-2014-3490). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3490 https://rhn.redhat.com/errata/RHSA-2014-1011.html ======================== Updated package in core/updates_testing: ======================== resteasy-3.0.1-3.1.mga4 resteasy-javadoc-3.0.1-3.1.mga4 from resteasy-3.0.1-3.1.mga4.src.rpm Assignee:
dmorganec =>
qa-bugs MGA4-64 on HP Probook 6555b No installation issues, apart from the surprise that this package calls +400 dependencies on my fairly default KDE workstation installation. CC:
(none) =>
herman.viaene MGA4-32 on Acer D620 Xfce installation. No installation issues, same surprise as above. Whiteboard:
MGA4-64-OK =>
MGA4-32-OK MGA4-64-OK Validating. Advisory uploaded. Please push to updates Thanks Whiteboard:
MGA4-32-OK MGA4-64-OK =>
advisory MGA4-32-OK MGA4-64-OK An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGASA-2014-0547.html Resolution:
(none) =>
FIXED |