Bug 858781
| Summary: | CVE-2012-3451 jbossws-cxf, apache-cxf: SOAPAction spoofing on document literal web services [fedora-17] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Jan Lieskovsky <jlieskov> |
| Component: | cxf | Assignee: | Patryk Obara <pobara> |
| Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 17 | CC: | bgeorges, mgoldman, pobara |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Release Note | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2012-12-20 15:34:56 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 851896 | ||
|
Description
Jan Lieskovsky
2012-09-19 16:42:53 UTC
Changing component to cxf. (In reply to comment #1) > Changing component to cxf. Thank you, Marek. So it is enough to correct this issue in 'cxf' package, and no update for jbossws-cxf one needed? (IOW jbossws-cxf being just 'cxf' stack for JBoss applications?) Let me know (if jbossws-cxf one would still be needed, I can create one). Thank you, Jan. -- Jan iankko Lieskovsky / Red Hat Security Response Team Hi Jan, Since in Fedora we do not bundle anything with jbossws-cxf (unline upstream binary packages) the correct way to create CVE's related to Apache CXF is to use 'cxf' component, because this is the only package in Fedora that contains the Apache CXF code. --Marek cxf-2.4.9-2.fc17 has been submitted as an update for Fedora 17. https://admin.fedoraproject.org/updates/cxf-2.4.9-2.fc17 cxf-2.4.9-2.fc18 has been submitted as an update for Fedora 18. https://admin.fedoraproject.org/updates/cxf-2.4.9-2.fc18 Package cxf-2.4.9-2.fc18: * should fix your issue, * was pushed to the Fedora 18 testing repository, * should be available at your local mirror within two days. Update it with: # su -c 'yum update --enablerepo=updates-testing cxf-2.4.9-2.fc18' as soon as you are able to. Please go to the following url: https://admin.fedoraproject.org/updates/FEDORA-2012-15293/cxf-2.4.9-2.fc18 then log in and leave karma (feedback). cxf-2.4.9-2.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report. |