Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Red Hat 7: RHSA-2018:1780-01 Important: Xmlrpc Java Deserialization

Redhat Large Esm H500
An update for xmlrpc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: xmlrpc security update
Advisory ID:       RHSA-2018:1780-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2018:1780
Issue date:        2018-05-31
CVE Names:         CVE-2016-5003 
====================================================================
1. Summary:

An update for xmlrpc is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux Client Optional (v. 7) - noarch
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch
Red Hat Enterprise Linux Server Optional (v. 7) - noarch
Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch
Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - noarch

3. Description:

Apache XML-RPC is a Java implementation of XML-RPC, a popular protocol that
uses XML over HTTP to implement remote procedure calls.

Security Fix(es):

* xmlrpc: Deserialization of untrusted Java object through
 tag (CVE-2016-5003)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1508123 - CVE-2016-5003 xmlrpc: Deserialization of untrusted Java object through  tag

6. Package List:

Red Hat Enterprise Linux Client Optional (v. 7):

Source:
xmlrpc-3.1.3-9.el7_5.src.rpm

noarch:
xmlrpc-client-3.1.3-9.el7_5.noarch.rpm
xmlrpc-common-3.1.3-9.el7_5.noarch.rpm
xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm
xmlrpc-server-3.1.3-9.el7_5.noarch.rpm

Red Hat Enterprise Linux ComputeNode Optional (v. 7):

Source:
xmlrpc-3.1.3-9.el7_5.src.rpm

noarch:
xmlrpc-client-3.1.3-9.el7_5.noarch.rpm
xmlrpc-common-3.1.3-9.el7_5.noarch.rpm
xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm
xmlrpc-server-3.1.3-9.el7_5.noarch.rpm

Red Hat Enterprise Linux Server Optional (v. 7):

Source:
xmlrpc-3.1.3-9.el7_5.src.rpm

noarch:
xmlrpc-client-3.1.3-9.el7_5.noarch.rpm
xmlrpc-common-3.1.3-9.el7_5.noarch.rpm
xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm
xmlrpc-server-3.1.3-9.el7_5.noarch.rpm

Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7):

Source:
xmlrpc-3.1.3-9.el7_5.src.rpm

noarch:
xmlrpc-client-3.1.3-9.el7_5.noarch.rpm
xmlrpc-common-3.1.3-9.el7_5.noarch.rpm
xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm
xmlrpc-server-3.1.3-9.el7_5.noarch.rpm

Red Hat Enterprise Linux Workstation Optional (v. 7):

Source:
xmlrpc-3.1.3-9.el7_5.src.rpm

noarch:
xmlrpc-client-3.1.3-9.el7_5.noarch.rpm
xmlrpc-common-3.1.3-9.el7_5.noarch.rpm
xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm
xmlrpc-server-3.1.3-9.el7_5.noarch.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2016-5003
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2018 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBWxBkstzjgjWX9erEAQggqA//dlcYLvde6gB/yuEl0YUmLhco7yTKP+N7
Lc8YKYb0VrKndhhnBE7YgnFOIKcF//zYGkwuqQEQv3zCQEkWJDDuxEHEz6pryjAY
on4NDPdyFAB1hMxW+F2qb6mwpD6yXtwtGpmyRTD9J/Crr3ziFG4e4R6Vt/E9GfFr
n8XK/pVK8dDO/8JRH7iwbXIlxtMymb265U4LTq2nIBxoXmdEq2FIpnX5Mbq1Ay8z
6M1eHgOxCF2T6BweDHl+vdJzHBoE8cCYr3kbXvfhnfaBpoHQbJw9nDCSVBtrtxka
BryRCpyNAMQv7mmgarNb6g1IvVB6CQl/Iw63E3yAV4Svy7yx/Q0oRkLYT38A5pz+
cwJHW1Jb6tn3K5q1NtpmLwyp82ZbjzZfg85ONUM6KIFzX9UBW0No9doULL5Jb3f5
iCI4rDrqCgb1bL8PojXktIcFaStnTHZlRA+47jbY/yfnfyNSwEi4QQLQjDGV4o8h
B2v6Y3qfaQe0P/33K0AuwGEImM3giC120GydRwpYWM05olapXYhaClE8yUAv3oD6
gGYknqp7n0SBIhUJwOBqS1Gj1OR6StQeOlUc+b6xUMoiS2+6MSSQAvbeC0tVp+bf
5ddGtjxFeSR9X9LqsvEMftNlerMuya0bmpp0i7orRokvdlE7iOPZXRhLuQU314Qa
GmVw5ajXqCk=PZWM
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
This email address is being protected from spambots. You need JavaScript enabled to view it.

Red Hat 7: RHSA-2018:1780-01 Important: Xmlrpc Java Deserialization

red hat
Calendar Grey May 31, 2018
Dist Redhat Esm H88
A crucial patch for xmlrpc security has been released for Red Hat Enterprise Linux 7. Discover the implications of this update.
An update for xmlrpc is now available for Red Hat Enterprise Linux 7

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Apache XML-RPC is a Java implementation of XML-RPC, a popular protocol that uses XML over HTTP to implement remote procedure calls.
Security Fix(es):
* xmlrpc: Deserialization of untrusted Java object through tag (CVE-2016-5003)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2016-5003 https://access.redhat.com/security/updates/classification/#important

Package List

Red Hat Enterprise Linux Client Optional (v. 7):
Source: xmlrpc-3.1.3-9.el7_5.src.rpm
noarch: xmlrpc-client-3.1.3-9.el7_5.noarch.rpm xmlrpc-common-3.1.3-9.el7_5.noarch.rpm xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm xmlrpc-server-3.1.3-9.el7_5.noarch.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
Source: xmlrpc-3.1.3-9.el7_5.src.rpm
noarch: xmlrpc-client-3.1.3-9.el7_5.noarch.rpm xmlrpc-common-3.1.3-9.el7_5.noarch.rpm xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm xmlrpc-server-3.1.3-9.el7_5.noarch.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
Source: xmlrpc-3.1.3-9.el7_5.src.rpm
noarch: xmlrpc-client-3.1.3-9.el7_5.noarch.rpm xmlrpc-common-3.1.3-9.el7_5.noarch.rpm xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm xmlrpc-server-3.1.3-9.el7_5.noarch.rpm
Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7):
Source: xmlrpc-3.1.3-9.el7_5.src.rpm
noarch: xmlrpc-client-3.1.3-9.el7_5.noarch.rpm xmlrpc-common-3.1.3-9.el7_5.noarch.rpm xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm xmlrpc-server-3.1.3-9.el7_5.noarch.rpm
Red Hat Enterprise Linux Workstation Optional (v. 7):
Source: xmlrpc-3.1.3-9.el7_5.src.rpm
noarch: xmlrpc-client-3.1.3-9.el7_5.noarch.rpm xmlrpc-common-3.1.3-9.el7_5.noarch.rpm xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm xmlrpc-server-3.1.3-9.el7_5.noarch.rpm


Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2018:1780-01
Product: Red Hat Enterprise Linux
Issue date: 2018-05-31

Topic

An update for xmlrpc is now available for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux Client Optional (v. 7) - noarch

Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch

Red Hat Enterprise Linux Server Optional (v. 7) - noarch

Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch

Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - noarch

Bugs Fixed

1508123 - CVE-2016-5003 xmlrpc: Deserialization of untrusted Java object through tag

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here