Oval Definition:oval:com.redhat.rhsa:def:20071041
Revision Date:2007-11-26Version:602
Title:RHSA-2007:1041: java-1.5.0-ibm security update (Important)
Description:IBM's 1.5.0 Java release includes the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit.

  • The applet caching mechanism of the Java Runtime Environment (JRE) did not correctly process the creation of network connections. A remote attacker could use this flaw to create connections to services on machines other than the one that the applet was downloaded from. (CVE-2007-5232)

  • Multiple vulnerabilities existed in Java Web Start allowing an untrusted application to determine the location of the Java Web Start cache. (CVE-2007-5238)

  • Untrusted Java Web Start Applications or Java Applets were able to drag and drop a file to a Desktop Application. A user-assisted remote attacker could use this flaw to move or copy arbitrary files. (CVE-2007-5239)

  • The Java Runtime Environment allowed untrusted Java Applets or applications to display oversized Windows. This could be used by remote attackers to hide security warning banners. (CVE-2007-5240)

  • Unsigned Java Applets communicating via a HTTP proxy could allow a remote attacker to violate the Java security model. A cached malicious Applet could create network connections to services on other machines. (CVE-2007-5273)

    Unsigned Applets loaded with Mozilla Firefox or Opera browsers allowed remote attackers to violate the Java security model. A cached malicious Applet could create network connections to services on other machines. (CVE-2007-5274)

    All users of java-ibm-1.5.0 are advised to upgrade to these updated packages, that contain IBM's 1.5.0 SR6 Java release which resolves these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2007-5232
    CVE-2007-5238
    CVE-2007-5239
    CVE-2007-5240
    CVE-2007-5273
    CVE-2007-5274
    RHSA-2007:1041-01
    Platform(s):Supplementary for Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux 5 is installed
  • AND Package Information
  • java-1.5.0-ibm is earlier than 1:1.5.0.6-1jpp.1.el5
  • AND java-1.5.0-ibm is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.6-1jpp.1.el5
  • AND java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-ibm-demo is earlier than 1:1.5.0.6-1jpp.1.el5
  • AND java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-ibm-devel is earlier than 1:1.5.0.6-1jpp.1.el5
  • AND java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.6-1jpp.1.el5
  • AND java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.6-1jpp.1.el5
  • AND java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-ibm-plugin is earlier than 1:1.5.0.6-1jpp.1.el5
  • AND java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-ibm-src is earlier than 1:1.5.0.6-1jpp.1.el5
  • AND java-1.5.0-ibm-src is signed with Red Hat redhatrelease key
  • BACK