RHSA-2016:1931: Important: Red Hat JBoss Fuse/A-MQ 6.2.1 security and bug fix update
Red Hat JBoss Fuse, based on Apache ServiceMix, provides a small-footprint, flexible, open source enterprise service bus and integration platform. Red Hat JBoss A-MQ, based on Apache ActiveMQ, is a standards compliant messaging system that is tailored for use in mission critical applications.This patch is an update to Red Hat JBoss Fuse 6.2.1 and Red Hat JBoss A-MQ 6.2.1. It includes several bug fixes, which are documented in the readme.txt file included with the patch files.Security Fix(es): It was found that the fix for CVE-2012-6153 was incomplete: the code added to check that the server hostname matches the domain name in asubject's Common Name (CN) field in X.509 certificates was flawed. Aman-in-the-middle attacker could use this flaw to spoof an SSL server usinga specially crafted X.509 certificate. (CVE-2014-3577)Refer to the readme.txt file included with the patch files for installation instructions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2016:1931?
The severity of RHSA-2016:1931 is classified as important.
How do I fix RHSA-2016:1931?
To fix RHSA-2016:1931, you should apply the recommended patches for Red Hat JBoss Fuse and Red Hat JBoss A-MQ.
What software versions are affected by RHSA-2016:1931?
RHSA-2016:1931 affects specific versions of Red Hat JBoss Fuse and Red Hat JBoss A-MQ, which should be reviewed in your environment.
Is there a workaround for RHSA-2016:1931?
No specific workaround is documented for RHSA-2016:1931; patching is recommended to address the vulnerability.
Where can I find more information about RHSA-2016:1931?
More information about RHSA-2016:1931 can be found in the official Red Hat advisories and security updates.