[RHSA-2005:882-01] Important: openssl, php, mod_ssl, mod_imap security update for Stronghold

[email protected] Mon, 19 Dec 2005 12:35:22 -0500
Newsgroups gmane.linux.redhat.stronghold.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ---------------------------------------------------------------------
                   Red Hat Security Advisory

Synopsis:          Important: openssl, php, mod_ssl, mod_imap security up=
date for Stronghold
Advisory ID:       RHSA-2005:882-01
Advisory URL:      https://rhn.redhat.com/errata/RHSA-2005-882.html
Issue date:        2005-12-19
Updated on:        2005-12-19
Product:           Stronghold Cross Platform
CVE Names:         CVE-2004-1018 CVE-2004-1019 CVE-2005-0109 CVE-2005-296=
9 CVE-2005-2700 CVE-2005-3352 CVE-2005-3388 CVE-2005-3389 CVE-2005-3390
- ---------------------------------------------------------------------

1. Summary:

Updated versions of cross-platform Stronghold that fix security issues in
mod_ssl, mod_imap, OpenSSL, and PHP are now available.

This update has been rated as having important security impact by the Red
Hat Security Response Team.

2. Problem description:

Stronghold 4 contains a number of open source technologies, including
mod_ssl and the Apache HTTP Server.

Several security issues have been found that affect cross-platform
Stronghold 4:=20

A flaw in mod_imap when using the Referer directive with image maps.  Wit=
h
certain site configurations, a remote attacker could perform a cross-site
scripting attack if a victim can be forced to visit a malicious URL using
certain web browsers. (CVE-2005-3352)=20

A flaw in mod_ssl triggered if a virtual host was configured using
"SSLVerifyClient optional" and a directive "SSLVerifyClient required" is
set for a specific location.  For servers configured in this fashion, an
attacker may be able to access resources that should otherwise be
protected.  (CVE-2005-2700)=20

Flaws in shmop_write, pack, and unpack PHP functions.  These functions ar=
e
not normally passed user-supplied data, so would require a malicious PHP
script to be exploited.  (CVE-2004-1018)=20

Various flaws, including possible information disclosure, double free, an=
d
negative reference index array underflow in the deserialization code of
PHP.  PHP applications may use the unserialize function of untrusted user
data, which could allow a remote attacker to gain access to memory or
potentially execute arbitrary code.  (CVE-2004-1019)=20

A flaw in the way PHP registers global variables during a file upload
request.  A remote attacker could submit a carefully crafted
multipart/form-data POST request that would overwrite the $GLOBALS array,
altering expected script behavior, and possibly leading to the execution =
of
arbitrary PHP commands. Note that this vulnerability only affects
installations which have register_globals enabled in the PHP configuratio=
n
file, which is not a default or recommended option.  (CVE-2005-3390)

A flaw in the PHP parse_str() function. If a PHP script passes only one
argument to the parse_str() function, and the script can be forced to abo=
rt
execution during operation (for example due to the memory_limit setting),
the register_globals may be enabled even if it is disabled in the PHP
configuration file. This vulnerability only affects installations that ha=
ve
PHP scripts using the parse_str function in this way. (CVE-2005-3389)

A Cross-Site Scripting flaw in the phpinfo() function. If a victim can be
tricked into following a malicious URL to a site with a page displaying t=
he
phpinfo() output, it may be possible to inject javascript or HTML content
into the displayed page or steal data such as cookies.  This vulnerabilit=
y
only affects installations that allow users to view the output of the
phpinfo() function.  As the phpinfo() function outputs a large amount of
information about the current state of PHP, it should only be used during
debugging or if protected by authentication. (CVE-2005-3388)=20

OpenSSL contained a software work-around for a bug in SSL handling in
Microsoft Internet Explorer version 3.0.2.  This work-around is enabled i=
n
most servers that use OpenSSL to provide support for SSL and TLS.  Yutaka
Oiwa discovered that this work-around could allow an attacker, acting as =
a
"man in the middle", to force an SSL connection to use SSL 2.0 rather tha=
n
a stronger protocol such as SSL 3.0 or TLS 1.0.  (CAN-2005-2969)

Colin Percival reported a cache timing attack that could allow a maliciou=
s
local user to gain portions of cryptographic keys.  The OpenSSL library h=
as
been patched to add a new fixed-window mod_exp implementation as default
for RSA, DSA, and DH private-key operations.  This patch is designed to
mitigate cache timing and potentially related attacks.  (CVE-2005-0109)

Stronghold users are advised to upgrade to these updated packages, which
resolve these issues.

3. Solution:

Updated Stronghold 4 packages containing backported patches to correct
these issues are now available via the update agent service. Run the
following command from the Stronghold 4 install root to upgrade an existi=
ng
Stronghold 4 installation to the new package versions:

$ bin/agent

The Stronghold 4.0k patch release which contains these updated packages i=
s
also available from the download site.

After upgrading Stronghold, the server must be completely restarted by
running the following commands from the install root:

$ bin/stop-server
$ bin/start-server

For more information on how to upgrade between releases of Stronghold 4,
refer to http://stronghold.redhat.com/support/upgrade-sh4

4. References:

http://stronghold.redhat.com/support/upgrade-sh4
http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2004-1018
http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2004-1019
http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2005-0109
http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2005-2969
http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2005-2700
http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2005-3352
http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2005-3388
http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2005-3389
http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2005-3390

5. Contact:

The Red Hat security contact is <[email protected]>.  More contact
details at https://www.redhat.com/security/team/contact/

Copyright 2005 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQFDpu8vXlSAg2UNWIIRAtoCAJ9tIrm7Wnf1B+DS5f+n0PCKBb8faACfcZ78
QS+f7kFyiQVAHhPLQaAueoY=3D
=3DO0Xh
-----END PGP SIGNATURE-----