Red Hat addressed CVE-2014-0193, a low-severity denial-of-service flaw in Netty's WebSocket08FrameDecoder. An unauthenticated remote attacker could send a sequence of TextWebSocketFrame and ContinuationWebSocketFrame messages that caused uncontrolled memory aggregation, resulting in an OutOfMemoryException and potentially crashing or degrading an affected server. Netty fixed the issue in its 3.x and 4.x branches; Netty 3.2.x was not affected because it lacked the vulnerable WebSocket implementation.
The remediation was delivered to affected JBoss products through Red Hat security advisories, including RHSA-2014:1020 for JBoss EAP 6. Red Hat updated Netty to netty-3.6.9-1.Final_redhat_1.1.ep6.el6, incorporating upstream commit 4cc400ce2145a72820119b0eaab838d5d9263022, and verified the fix in EAP 6.3.0.ER10. Organizations operating affected JBoss deployments should apply the relevant Red Hat errata and verify that bundled Netty components are updated.

See affected versions and whether adversaries are exploiting it.
62 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Important advisory RHSA-2015:0720 and released Rollup Patch 4 for JBoss Fuse Service Works 6.0.0. The cumulative patch remediated numerous flaws, including Netty DoS, RESTEasy and Tomcat XXE, Mojarra XSS, Xerces-J XML DoS, request smuggling, and authorization bypasses.
Red Hat released Important Rollup Patch 1 for JBoss Fuse 6.1.0 and JBoss A-MQ 6.1.0. Beyond the Netty WebSocket DoS flaw, it addressed Shiro authentication bypass, Xalan-Java secure-processing bypass, CXF SAML validation, credential-exposure and denial-of-service flaws, Jolokia CSRF, and Spring XML internal-network discovery.
Red Hat released RHSA-2014:1351 to remediate CVE-2014-0193 in JBoss A-MQ 6.1. The update addressed remote memory exhaustion caused by aggregation of crafted WebSocket frames.
Red Hat issued RHSA-2014:1021 for JBoss EAP 6.3 and RHSA-2014:1019 for EAP 6 on RHEL 5. The updates addressed the Netty WebSocket DoS flaw and CVE-2014-3464, in which JAX-WS handlers could run despite failed authorization.
Red Hat's JBoss BRMS 6.0.2 update also remediated CVE-2014-0107, where malicious XSLT could bypass Xalan-Java secure-processing restrictions and potentially enable remote code execution depending on the classpath. It further fixed Smack XMPP certificate-validation and roster-IQ spoofing issues, CVE-2014-0363 and CVE-2014-0364.
Red Hat issued RHSA-2014:0818 to fix CVE-2014-0193 in JBoss BRMS 6.0.2. The Netty flaw enabled remote memory exhaustion and potential denial of service through crafted WebSocket frames.
Red Hat closed Bugzilla 1188983 as ERRATA for the required upgrade of JBoss HAL to jboss-hal-2.5.5-1.Final_redhat_1.1.ep6.el6 for RHEL 6. The issue was resolved through RHSA-2015:0847, which provided the updated files.
Red Hat closed Bugzilla 1182983 as ERRATA after requiring an upgrade of xml-commons-resolver-eap6 to 1.2.0-1.redhat_10.2.ep6.el6 for RHEL 6. The record directed users to RHSA-2015:0847 for updated files and did not identify a specific vulnerability or security impact.
Red Hat closed Bugzilla 1182989 as ERRATA for the required upgrade of the Java JSR-181 API and Sun Web Services Metadata API packages, including sun-ws-metadata-2.0-api 1.0.0.MR1_redhat_7 builds for RHEL 6. Users were directed to RHSA-2015:0847 for updated files; the record did not identify a specific vulnerability, CVE, impact, or exploitation status.
Red Hat closed Bugzilla 1188725 as ERRATA for the required upgrade of cal10n-eap6 to 0.7.7-1.redhat_1.1.ep6.el6. The record directed users to RHSA-2015:0847 and did not identify an underlying vulnerability, impact, affected systems, or exploitation status.
Red Hat closed Bugzilla 1167918 as ERRATA for a required upgrade of jcip-annotations-eap6 to 1.0.0-1.redhat_7.1.ep6.el6. The record directed users to RHSA-2015:0847 for remediation information and updated files, without identifying a specific vulnerability or security impact.
Red Hat included jboss-xnio-base-3.0.9-1.GA_redhat_1.1.ep6.el6 in the CR1 build and closed Bugzilla 1053228 as ERRATA. RHSA-2014:0171 provided the advisory information and updated RHEL 6 files.
Red Hat verified jboss-logmanager-1.5.2-1.Final_redhat_1.1.ep6.el6 in a CR3 build and closed Bugzilla 1052717 as ERRATA. RHSA-2014:0171 provided the updated RHEL 6 package; several related Bugzilla records were marked as duplicates.
Red Hat verified Netty 3.6.7.Final_redhat_1 builds in the CR3 build and closed Bugzilla 1053223 as ERRATA. RHSA-2014:0171 provided the updated RHEL 6 Netty files.
Red Hat verified the required jboss-marshalling upgrade in the CR3 build and closed Bugzilla 1053231 as ERRATA. Users were directed to RHSA-2014:0170 for updated files and remediation information.
Red Hat closed Bugzilla 1106586 as ERRATA for the upgrade to picketbox 4.0.19.SP8-redhat-1 on RHEL 5. Users were directed to RHSA-2014:0798 for advisory details and updated files; the record did not identify a specific vulnerability or security impact.
Red Hat closed Bugzilla 1105658 as ERRATA and directed users to RHSA-2014:0798 for updated files requiring an upgrade to jboss-security-negotiation 2.2.10.Final-redhat-1. The record did not identify an underlying vulnerability, severity, or technical security impact.
Red Hat closed Bugzilla 1106583 as ERRATA for an upgrade to jbossts 4.17.15.Final-redhat-5 for RHEL 5. Users were directed to RHSA-2014:0798 for advisory details and updated files; the record did not identify a specific vulnerability or security impact.
Red Hat closed Bugzilla 1103873 as ERRATA and directed users to RHSA-2014:0798 for updated files requiring an upgrade to jboss-aesh 0.33.12.redhat-1. The record did not identify an underlying vulnerability, severity, or technical security impact.
Red Hat closed Bugzilla 1106546 as ERRATA for the jboss-xnio-base 3.0.10.GA-redhat-1 upgrade. Users were directed to RHSA-2014:0798 for updated files; the record did not identify an underlying vulnerability or security impact.
Red Hat closed Bugzilla 1104167 as ERRATA after an upgrade to jbossweb 7.3.2.Final-redhat-1 was made available for RHEL 5. Users were directed to RHSA-2014:0798 for remediation details and updated files.
Red Hat verified the JBoss JSTL API specification package upgrade to jboss-jstl-api_1.2_spec 1.0.6.Final_redhat_1 builds in JBoss EAP 6.3.0.ER10 and closed Bugzilla 1069414 as ERRATA. Users were directed to RHSA-2014:1020 for updated files; the record did not identify a specific vulnerability or security impact.
Red Hat updated mod_jk to builds mod_jk-1.2.40-1.redhat_1.ep6.el6 and mod_jk-1.2.40-2.redhat_1.ep6.el6 for RHEL 6. Bugzilla 1092088 was verified in JBoss EAP 6.3.0.ER10 and closed as ERRATA with RHSA-2014:1020.
Fedora 20 received fixed package resteasy-3.0.6-3.fc20 in its stable repository. The update addressed CVE-2014-3490, which allowed external parameter entities despite a setting intended to disable entity-reference expansion.
Red Hat issued RHSA-2015:0765 for JBoss Data Virtualization 6.0.0. The update addressed the Netty memory-exhaustion DoS, RESTEasy XXE, Tomcat/JBoss Web XSLT XXE, and Mojarra XSS vulnerabilities.
Red Hat issued RHSA-2015:0675 for JBoss Data Virtualization 6.1.0, addressing the Netty DoS, RESTEasy XXE, Tomcat/JBoss Web XSLT XXE, and Mojarra XSS flaws.
Fedora 21 received tomcat-7.0.59-1.fc21 in its stable repository, fixing CVE-2014-0096. The vulnerability allowed external entity definitions in user-supplied XSLT files handled by Tomcat or JBoss Web DefaultServlet.
Red Hat released RHSA-2015:0234 for JBoss BPM Suite 6.0.3 and RHSA-2015:0235 for JBoss BRMS 6.0.3. These updates remediated the Netty DoS, RESTEasy XXE, Tomcat/JBoss Web XSLT XXE, and Mojarra XSS issues.
Red Hat closed Bugzilla 1179417 as ERRATA after RHSA-2015:0217 provided hornetq-2.3.21.2-1.Final_redhat_1.1.ep6.el6 for RHEL 6. The upgrade was sourced from HornetQ commit c6729cbcef1098fdf97cc6764cc28c9ca2f259ea; the record did not identify a specific vulnerability or security impact.
Red Hat closed Bugzilla 1179428 as ERRATA after releasing RHSA-2015:0217, which provided jbossweb-7.4.10-1.Final_redhat_1.1.ep6.el6 for RHEL 6. The upgrade was sourced from JBoss Web tag JBOSSWEB_7_4_10_FINAL revision 2580.
Red Hat verified jboss-as-console 2.2.8.Final-redhat-1 in JBoss EAP 6.3.0.ER10 and closed Bugzilla 1072566 as ERRATA, directing users to RHSA-2014:1020. The record tracked a required package upgrade and did not identify a specific vulnerability or security impact.
Red Hat verified the glassfish-jsf-eap6 2.1.27-6.redhat_8.1.ep6.el6 upgrade during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1066503 as ERRATA. Users were directed to RHSA-2014:0344 for updated files; Bugzilla 1053220 was marked as a duplicate.
Red Hat verified the jbossws-cxf 4.2.4.Final_redhat_1 upgrade during EAP 6.2.2 CP-CR3 testing and closed Bugzilla 1067648 as ERRATA. Users were directed to RHSA-2014:0344 for updated files and remediation information.
Red Hat verified the required jbossas-javadocs upgrade, including 7.3.2-2.Final_redhat_2 builds, during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1069601 as ERRATA. Users were directed to RHSA-2014:0344 for updated files and advisory information.
Red Hat verified the jbossweb 7.3.1.Final_redhat_1 upgrade during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1076133 as ERRATA. Users were directed to RHSA-2014:0344 for updated files; the record did not identify a specific vulnerability or security impact.
Red Hat verified apache-cxf-2.7.10-1.redhat_1.1.ep6.el6 during EAP 6.2.2 CP-CR3 testing and closed Bugzilla 1067508 as ERRATA. RHSA-2014:0344 provided the updated Apache CXF files; the record did not identify a CVE or specific security impact.
Red Hat verified jboss-metadata-7.0.9-1.Final_redhat_1.1.ep6.el6 during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1066497 as ERRATA. Users were directed to RHSA-2014:0344 for updated files and advisory information.
Red Hat verified the jboss-remote-naming 1.0.8-1.Final_redhat_1.1.ep6.el6 upgrade during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1066512 as ERRATA. Users were directed to RHSA-2014:0344 for the updated files and advisory information.
Red Hat verified the jboss-ejb-client 1.0.25.Final_redhat_1 upgrade during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1067100 as ERRATA. Users were directed to RHSA-2014:0344 for the RHEL 6 updated files.
Red Hat verified jboss-el-api_2.2_spec-1.0.4-2.Final_redhat_1.1.ep6.el6 during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1076114 as ERRATA. Users were directed to RHSA-2014:0344 for the updated files and advisory information; the record did not identify a specific vulnerability or security impact.
Red Hat verified jboss-modules-1.3.3-1.Final_redhat_1.1.ep6.el6 during JBoss EAP 6.2.2.CP-CR3 testing and closed Bugzilla 1076167 as ERRATA. Users were directed to RHSA-2014:0344 for updated files and advisory information.
Red Hat verified jboss-remoting3-3.2.19-1.GA_redhat_1.1.ep6.el6 during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1068711 as ERRATA. RHSA-2014:0344 provided the updated files for the required JBoss Remoting upgrade.
Red Hat verified the required upgrade of jboss-modules to 1.3.3.Final-redhat-1 during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1076168 as ERRATA. Users were directed to RHSA-2014:0343 for updated files and advisory information.
Red Hat verified the jboss-el-api_2.2_spec 1.0.4.Final-redhat-1 upgrade during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1076115 as ERRATA. Users were directed to RHSA-2014:0343 for updated files and remediation information; the record did not identify a CVE, underlying vulnerability, or security impact.
Red Hat verified the apache-cxf 2.7.10.redhat-1 upgrade during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1067509 as ERRATA. Users were directed to RHSA-2014:0343 for updated files and remediation information; the record did not identify a specific vulnerability or security impact.
Red Hat verified the required jboss-metadata 7.0.9.Final-redhat-1 upgrade during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1066498 as ERRATA. Users were directed to RHSA-2014:0343 for updated files and advisory information.
Red Hat verified the jboss-ejb-client 1.0.25.Final-redhat-1 upgrade during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1067101 as ERRATA. Users were directed to RHSA-2014:0343 for updated files; the record did not identify a CVE, underlying vulnerability, or specific security impact.
Red Hat verified the required jboss-remote-naming 1.0.8.Final-redhat-1 upgrade during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1066513 as ERRATA. Users were directed to RHSA-2014:0343 for remediation information and updated files; the record did not identify a specific vulnerability or security impact.
Red Hat verified the glassfish-jsf-eap6 2.1.27.redhat-8 upgrade during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1066504 as ERRATA. Users were directed to RHSA-2014:0343 for updated files and advisory details; Bugzilla 1053221 was marked as a duplicate.
Red Hat verified the required upgrade of jboss-jsf-api_2.1_spec to 2.1.27.Final-redhat-1 during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1066506 as ERRATA. Users were directed to RHSA-2014:0343 for advisory information and updated files; Bugzilla 1053269 was marked as a duplicate.
Red Hat verified the required jbossws-cxf 4.2.4.Final-redhat-1 upgrade during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1067649 as ERRATA. Users were directed to RHSA-2014:0343 for updated files and advisory details; the record did not identify a specific vulnerability or security impact.
Red Hat verified the required jboss-remoting3 3.2.19.GA-redhat-1 upgrade during EAP-6.2.2.CP-CR3 testing and closed Bugzilla 1068712 as ERRATA. Users were directed to RHSA-2014:0343 for updated files and advisory information.
Red Hat released JBoss Operations Network 3.3.0 as a replacement for 3.2.3, rated Important in aggregate. The release fixed SSL hostname-validation, RESTEasy XXE, HawtJNI temporary-file, and world-readable audit-log vulnerabilities.
Red Hat verified RESTEasy 2.3.8.Final_redhat_3 builds for JBoss EAP 6.3.0.ER10 and closed Bugzilla 1071412 as ERRATA under RHSA-2014:1020. Bugzilla 1067108 was marked as a duplicate of this upgrade record.
Red Hat verified the JBoss JAX-WS API specification package update to 2.0.2.Final_redhat_1 builds in JBoss EAP 6.3.0.ER10 and closed Bugzilla 1102512 as ERRATA. Users were directed to RHSA-2014:1020 for the updated files; the record did not identify a specific vulnerability or security impact.
Red Hat remediated Bugzilla 1102509 by updating the JBoss SAAJ API specification package to 1.0.3.Final_redhat_1 builds for RHEL 6. The fix was verified in JBoss EAP 6.3.0.ER10 and delivered through RHSA-2014:1020; the bug was closed as ERRATA.
Red Hat supplied and verified updated Netty, JBossWS, JBoss Remoting, JBoss Security Negotiation, JBoss Metadata, and JBoss Marshalling builds in EAP 6.3.0.ER10. The related Bugzilla records were closed as ERRATA and directed users to RHSA-2014:1020.
RESTEasy applied patches to its 2.3 and master branches and closed RESTEASY-1073, addressing an incomplete earlier fix that left external parameter entities enabled. The flaw could permit XML-request attackers to read files available to the application-server account.
Netty released fixed versions 3.6.9.Final, 3.7.1.Final, 3.8.2.Final, 3.9.1.Final, and 4.0.19.Final for CVE-2014-0193. The flaw let remote attackers send crafted WebSocket frames that consumed memory and could trigger an OutOfMemoryException.
Apache committed fixes for the DefaultServlet XSLT XXE flaw in Tomcat 6 and 7, while JBoss Web recorded an upstream fix in changeset 2427. A malicious application could use supplied XSLTs with external entities to bypass restrictions and disclose information.
Upstream Mojarra provided a patch for JAVASERVERFACES-3150 in SVN revision 12793. The flaw allowed unescaped content in outputText tags and raw EL expressions after script or style elements to enable XSS.
Apache Xerces-J addressed the malformed-XML CPU-exhaustion flaw in revision 1499506, and OpenJDK published a related JAXP fix for jdk7u. The issue could allow specially crafted XML declarations with long pseudo-attribute names to cause denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
50 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.