SHORT DESCRIPTION:
Provide fix for JBWEB-163.
LONG DESCRIPTION:
Patch for CVE-2009-3555.
MANUAL INSTALL INSTRUCTIONS:
Replace the existing %JBOSS_HOME%/server/%JBOSSCONF%/deploy/jboss-web.deployer/jbossweb.jar with the new jbossweb.jar
COMPATIBILITY:
4.2.0.GA CP08, 4.3.0.GA CP07
SUPERSEDES:
N/A
CREATOR:
Mike Millson
DATE:
5-March-2010
SHORT DESCRIPTION:
Provide fix for JBWEB-163.
LONG DESCRIPTION:
Patch for CVE-2009-3555.
MANUAL INSTALL INSTRUCTIONS:
Replace the existing %JBOSS_HOME%/server/%JBOSSCONF%/deploy/jboss-web.deployer/jbossweb.jar with the new jbossweb.jar
COMPATIBILITY:
4.2.0.GA CP08, 4.3.0.GA CP07
SUPERSEDES:
N/A
CREATOR:
Mike Millson
DATE:
5-March-2010
CVE-2009-3555 TLS: MITM attacks via session renegotiation