Oval Definition:oval:com.redhat.rhsa:def:20080594
Revision Date:2008-07-14Version:602
Title:RHSA-2008:0594: java-1.6.0-sun security update (Critical)
Description:The Java Runtime Environment (JRE) contains the software and tools that users need to run applets and applications written using the Java programming language.

  • A vulnerability was found in the Java Management Extensions (JMX) management agent, when local monitoring is enabled. This allowed remote attackers to perform illegal operations. (CVE-2008-3103)

  • Multiple vulnerabilities with unsigned applets were reported. A remote attacker could misuse an unsigned applet to connect to localhost services running on the host running the applet. (CVE-2008-3104)

  • Several vulnerabilities in the Java API for XML Web Services (JAX-WS) client and service implementation were found. A remote attacker who caused malicious XML to be processed by a trusted or untrusted application was able access URLs or cause a denial of service. (CVE-2008-3105, CVE-2008-3106)

  • A JRE vulnerability could be triggered by an untrusted application or applet. A remote attacker could grant an untrusted applet or application extended privileges such as being able to read and write local files, or execute local programs. (CVE-2008-3107)

  • Several vulnerabilities within the JRE scripting support were reported. A remote attacker could grant an untrusted applet extended privileges such as reading and writing local files, executing local programs, or querying the sensitive data of other applets. (CVE-2008-3109, CVE-2008-3110)

  • A vulnerability in Java Web Start was found. A remote attacker was able to create arbitrary files with the permissions of the user running the untrusted Java Web Start application. (CVE-2008-3112)

  • Another vulnerability in Java Web Start when processing untrusted applications was reported. An attacker was able to acquire sensitive information, such as the cache location. (CVE-2008-3114)

    Users of java-1.6.0-sun should upgrade to these updated packages, which correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-3103
    CVE-2008-3104
    CVE-2008-3105
    CVE-2008-3106
    CVE-2008-3107
    CVE-2008-3109
    CVE-2008-3110
    CVE-2008-3112
    CVE-2008-3114
    RHSA-2008:0594-01
    Platform(s):Supplementary for Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux 5 is installed
  • AND Package Information
  • java-1.6.0-sun is earlier than 1:1.6.0.7-1jpp.1.el5
  • AND java-1.6.0-sun is signed with Red Hat redhatrelease key
  • OR
  • java-1.6.0-sun-demo is earlier than 1:1.6.0.7-1jpp.1.el5
  • AND java-1.6.0-sun-demo is signed with Red Hat redhatrelease key
  • OR
  • java-1.6.0-sun-devel is earlier than 1:1.6.0.7-1jpp.1.el5
  • AND java-1.6.0-sun-devel is signed with Red Hat redhatrelease key
  • OR
  • java-1.6.0-sun-jdbc is earlier than 1:1.6.0.7-1jpp.1.el5
  • AND java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease key
  • OR
  • java-1.6.0-sun-plugin is earlier than 1:1.6.0.7-1jpp.1.el5
  • AND java-1.6.0-sun-plugin is signed with Red Hat redhatrelease key
  • OR
  • java-1.6.0-sun-src is earlier than 1:1.6.0.7-1jpp.1.el5
  • AND java-1.6.0-sun-src is signed with Red Hat redhatrelease key
  • BACK