Oval Definition:oval:com.redhat.rhsa:def:20162604
Revision Date:2016-11-03Version:641
Title:RHSA-2016:2604: resteasy-base security and bug fix update (Important)
Description:RESTEasy contains a JBoss project that provides frameworks to help build RESTful Web Services and RESTful Java applications. It is a fully certified and portable implementation of the JAX-RS specification.

Security Fix(es):

  • It was discovered that under certain conditions RESTEasy could be forced to parse a request with SerializableProvider, resulting in deserialization of potentially untrusted data. An attacker could possibly use this flaw to execute arbitrary code with the permissions of the application using RESTEasy. (CVE-2016-7050)

    Red Hat would like to thank Mikhail Egorov (Odin) for reporting this issue.

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-7050
    RHSA-2016:2604
    RHSA-2016:2604-01
    RHSA-2016:2604-02
    RHSA-2016:2604-02
    Platform(s):Red Hat Enterprise Linux 7
    Red Hat Enterprise Linux 7 (please do not use for >= RHEL-7.5)
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • resteasy-base is earlier than 0:3.0.6-4.el7
  • AND resteasy-base is signed with Red Hat redhatrelease2 key
  • resteasy-base-atom-provider is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-atom-provider is signed with Red Hat redhatrelease2 key
  • resteasy-base-client is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-client is signed with Red Hat redhatrelease2 key
  • resteasy-base-jackson-provider is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-jackson-provider is signed with Red Hat redhatrelease2 key
  • resteasy-base-javadoc is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-javadoc is signed with Red Hat redhatrelease2 key
  • resteasy-base-jaxb-provider is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-jaxb-provider is signed with Red Hat redhatrelease2 key
  • resteasy-base-jaxrs is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-jaxrs is signed with Red Hat redhatrelease2 key
  • resteasy-base-jaxrs-all is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-jaxrs-all is signed with Red Hat redhatrelease2 key
  • resteasy-base-jaxrs-api is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-jaxrs-api is signed with Red Hat redhatrelease2 key
  • resteasy-base-jettison-provider is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-jettison-provider is signed with Red Hat redhatrelease2 key
  • resteasy-base-providers-pom is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-providers-pom is signed with Red Hat redhatrelease2 key
  • resteasy-base-resteasy-pom is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-resteasy-pom is signed with Red Hat redhatrelease2 key
  • resteasy-base-tjws is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-tjws is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 7 Client is installed
  • OR Red Hat Enterprise Linux 7 Server is installed
  • OR Red Hat Enterprise Linux 7 Workstation is installed
  • OR Red Hat Enterprise Linux 7 ComputeNode is installed
  • AND Package Information
  • resteasy-base-jaxb-provider is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-jaxb-provider is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-providers-pom is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-providers-pom is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-jackson-provider is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-jackson-provider is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-atom-provider is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-atom-provider is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-jaxrs is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-jaxrs is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-tjws is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-tjws is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-javadoc is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-javadoc is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-client is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-client is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-jaxrs-api is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-jaxrs-api is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base is earlier than 0:3.0.6-4.el7
  • AND resteasy-base is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-jettison-provider is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-jettison-provider is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-resteasy-pom is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-resteasy-pom is signed with Red Hat redhatrelease2 key
  • OR
  • resteasy-base-jaxrs-all is earlier than 0:3.0.6-4.el7
  • AND resteasy-base-jaxrs-all is signed with Red Hat redhatrelease2 key
  • BACK