-
1. Re: JBoss patches/security updates (hotfix)
fjuma Mar 26, 2012 4:24 PM (in response to proque_cu)proque_cu wrote:
Was able to find: https://issues.jboss.org/browse/JBPAPP-2274 how do I go ahead and apply this patch?
Since you're using JBoss AS 5.1.0.GA, it's probably better to use the corresponding patch from here: https://issues.jboss.org/browse/JBAS-7105
This patch can be applied as follows from the jboss-5.1.0.GA-src directory:
patch -p0 < /path/to/JBAS-7105.patch
-
2. Re: JBoss patches/security updates (hotfix)
proque_cu Mar 26, 2012 3:36 PM (in response to fjuma)Hi Farah,
Tried going to your link and getting:
Permission Violation
It seems that you have tried to perform an operation which you are not permitted to perform.
If you think this message is wrong, please contact your JIRA administrators.
went to: https://issues.jboss.org/browse/JBPAPP-2274 as per CVE-2009-2405
-
3. Re: JBoss patches/security updates (hotfix)
fjuma Mar 26, 2012 3:51 PM (in response to proque_cu)Sorry about that. I just checked and the two patches are actually identical.
JBPAPP-2274.patch can be applied as described above, i.e., patch -p0 < /path/to/patch/file
-
4. Re: JBoss patches/security updates (hotfix)
proque_cu Mar 26, 2012 4:26 PM (in response to fjuma)No worries,
So do I apply this to the source files of JBoss, I usually get the zip containing the binary files from: http://sourceforge.net/projects/jboss/files/JBoss/JBoss-5.1.0.GA via http://www.jboss.org/jbossas/downloads
Sorry again, still a little bit lost, after opening the .patch file do see: varia/src/resources/jmx/html/displayMBeans.jsp which makes reference to a file that does exists in my JBoss /server/default configuration but also see the reference to src... Source
So would this patch be targeting the source files to later be compiled or just the regular folder that I have?
Thanks again for your help.
-
5. Re: JBoss patches/security updates (hotfix)
fjuma Mar 26, 2012 5:38 PM (in response to proque_cu)Yes, this patch is meant to be applied to the source files. jboss-5.1.0.GA-src.tar.gz can be found here as well: http://sourceforge.net/projects/jboss/files/JBoss/JBoss-5.1.0.GA
-
6. Re: JBoss patches/security updates (hotfix)
proque_cu Mar 27, 2012 4:39 PM (in response to fjuma)Hi,
So the patch works well with the web-console.war files, but doesn't want to play with the JMX portion:
Edited the file and removed the web-console piece and left the JMX one, reverted the files from the previously made backup and still spitting the same on this section.
patch -p0 < JBPAPP-2274-JMX.patch
patching file varia/src/resources/jmx/html/inspectMBean.jsp
Hunk #1 succeeded at 166 with fuzz 2 (offset 144 lines).
Hunk #2 FAILED at 228.
Hunk #3 FAILED at 317.
2 out of 3 hunks FAILED -- saving rejects to file varia/src/resources/jmx/html/inspectMBean.jsp.rej
patching file varia/src/resources/jmx/html/displayMBeans.jsp
Hunk #1 succeeded at 25 with fuzz 2 (offset 24 lines).
Hunk #2 FAILED at 92.
1 out of 2 hunks FAILED -- saving rejects to file varia/src/resources/jmx/html/displayMBeans.jsp.rej
Waiting to hear back if it addressed the web-console issues which were the ones raised up.
Will update the thread
Thanks again