Oval Definition:oval:com.redhat.rhsa:def:20080244
Revision Date:2008-04-28Version:602
Title:RHSA-2008:0244: java-1.5.0-bea security update (Moderate)
Description:The BEA WebLogic JRockit 1.5.0_14 JRE and SDK contain BEA WebLogic JRockit Virtual Machine 1.5.0_14, and are certified for the Java 5 Platform, Standard Edition, v1.5.0.

  • A flaw was found in the Java XSLT processing classes. An untrusted application or applet could cause a denial of service, or execute arbitrary code with the permissions of the user running the JRE. (CVE-2008-1187)

  • A flaw was found in the JRE image parsing libraries. An untrusted application or applet could cause a denial of service, or possibly execute arbitrary code with the permissions of the user running the JRE. (CVE-2008-1193)

  • A flaw was found in the JRE color management library. An untrusted application or applet could trigger a denial of service (JVM crash). (CVE-2008-1194)

    The vulnerabilities concerning applets listed above can only be triggered in java-1.5.0-bea, by calling the "appletviewer" application.

    Users of java-1.5.0-bea are advised to upgrade to these updated packages, which resolve these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-1187
    CVE-2008-1193
    CVE-2008-1194
    RHSA-2008:0244-01
    Platform(s):Supplementary for Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux 5 is installed
  • AND Package Information
  • java-1.5.0-bea is earlier than 0:1.5.0.14-1jpp.2.el5
  • AND java-1.5.0-bea is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-bea-demo is earlier than 0:1.5.0.14-1jpp.2.el5
  • AND java-1.5.0-bea-demo is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-bea-devel is earlier than 0:1.5.0.14-1jpp.2.el5
  • AND java-1.5.0-bea-devel is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-bea-jdbc is earlier than 0:1.5.0.14-1jpp.2.el5
  • AND java-1.5.0-bea-jdbc is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-bea-missioncontrol is earlier than 0:1.5.0.14-1jpp.2.el5
  • AND java-1.5.0-bea-missioncontrol is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-bea-src is earlier than 0:1.5.0.14-1jpp.2.el5
  • AND java-1.5.0-bea-src is signed with Red Hat redhatrelease key
  • BACK