axis-1.2.1-7.3.AXS4

エラータID: AXSA:2013-129:01

Release date: 
Friday, March 8, 2013 - 14:35
Subject: 
axis-1.2.1-7.3.AXS4
Affected Channels: 
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity: 
High
Description: 

Apache AXIS is an implementation of the SOAP ("Simple Object Access Protocol") submission to W3C.

From the draft W3C specification:

SOAP is a lightweight protocol for exchange of information in a decentralized, distributed environment. It is an XML based protocol that consists of three parts: an envelope that defines a framework for describing what is in a message and how to process it, a set of encoding rules for expressing instances of application-defined datatypes, and a convention for representing remote procedure calls and responses.

This project is a follow-on to the Apache SOAP project.

Security issues fixed with this release:

• CVE-2012-5784
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. axis-1.2.1-7.3.AXS4.src.rpm
    MD5: cfdc88366935f6e23fba5f81acf76d51
    SHA-256: f24f8bcb35a6da0af5ec8f425c0a7dd40d35e0764cf95dc9c021645531ec30e2
    Size: 10.87 MB

Asianux Server 4 for x86
  1. axis-1.2.1-7.3.AXS4.noarch.rpm
    MD5: 2212298ba98a14af38f3283be3799500
    SHA-256: 6d2f3fc9617ba3238af08526230e49aeb1c77c896f4f046d2b8e6f52d6687d18
    Size: 1.49 MB

Asianux Server 4 for x86_64
  1. axis-1.2.1-7.3.AXS4.noarch.rpm
    MD5: 8625cc79231e8ac35583fc4929cfbe2e
    SHA-256: c2beaa824301a1cc96be7b8375eeac8dd5832c87f7effa4a4db3882e3d1f38a6
    Size: 1.49 MB