Important jboss-ec2-eap security, bug fix, and enhancement update
-----BEGIN PGP SIGNED MESSAGE-----
Red Hat Security Advisory
Synopsis: Important: jboss-ec2-eap security, bug fix, and enhancement update
Advisory ID: RHSA-2017:0829-01
Product: Red Hat JBoss Enterprise Application Platform
Advisory URL: https://rhn.redhat.com/errata/RHSA-2017-0829.html
Issue date: 2017-03-22
CVE Names: CVE-2016-6346 CVE-2016-8657 CVE-2017-6056
An update for jboss-ec2-eap is now available for Red Hat JBoss Enterprise
Application Platform 6.4 for RHEL 6.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server - noarch
The jboss-ec2-eap packages provide scripts for Red Hat JBoss Enterprise
Application Platform running on the Amazon Web Services (AWS) Elastic
Compute Cloud (EC2).
With this update, the jboss-ec2-eap package has been updated to ensure
compatibility with Red Hat JBoss Enterprise Application Platform 6.4.14.
* It was discovered that EAP packages in certain versions of Red Hat
Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas
configuration files. The file is writable to jboss group (root:jboss, 664).
On systems using classic /etc/init.d init scripts (i.e. on Red Hat
Enterprise Linux 6 and earlier), the file is sourced by the jboss init
script and its content executed with root privileges when jboss service is
started, stopped, or restarted. (CVE-2016-8657)
* It was discovered that a programming error in the processing of HTTPS
requests in the Apache Tomcat servlet and JSP engine may result in denial
of service via an infinite loop. (CVE-2017-6056)
* It was found that GZIPInterceptor is enabled when not necessarily
required in RESTEasy. An attacker could use this flaw to launch a Denial of
Service attack. (CVE-2016-6346)
Red Hat would like to thank Mikhail Egorov (Odin) for reporting the
Before applying this update, back up your existing Red Hat JBoss Enterprise
Application Platform installation and deployed applications.
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
5. Bugs fixed (https://bugzilla.redhat.com/):
1372120 - CVE-2016-6346 RESTEasy: Abuse of GZIPInterceptor in RESTEasy can lead to denial of service attack
1400343 - CVE-2016-8657 jboss: jbossas writable config files allow privilege escalation
1422148 - CVE-2017-6056 tomcat: Infinite loop in the processing of https requests
6. Package List:
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server:
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
The Red Hat security contact is <secalert redhat com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2017 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
-----END PGP SIGNATURE-----