Oval Definition:oval:com.redhat.rhsa:def:20080906
Revision Date:2008-10-24Version:602
Title:RHSA-2008:0906: java-1.6.0-ibm security update (Critical)
Description:The IBM 1.6.0 Java release includes the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit.

A flaw was found in the Java Management Extensions (JMX) management agent. When local monitoring is enabled, remote attackers could use this flaw to perform illegal operations. (CVE-2008-3103)

  • Several flaws involving the handling of unsigned applets were found. A remote attacker could misuse an unsigned applet in order to connect to services on the host running the applet. (CVE-2008-3104)

  • Several flaws in the Java API for XML Web Services (JAX-WS) client and the JAX-WS service implementation were found. A remote attacker who could cause malicious XML to be processed by an application could access URLs, or cause a denial of service. (CVE-2008-3105, CVE-2008-3106)

  • Several flaws within the Java Runtime Environment (JRE) scripting support were found. A remote attacker could grant an untrusted applet extended privileges, such as reading and writing local files, executing local programs, or querying the sensitive data of other applets. (CVE-2008-3109, CVE-2008-3110)

  • A flaw in Java Web Start was found. Using an untrusted Java Web Start application, a remote attacker could create or delete arbitrary files with the permissions of the user running the untrusted application. (CVE-2008-3112)

  • A flaw in Java Web Start when processing untrusted applications was found. An attacker could use this flaw to acquire sensitive information, such as the location of the cache. (CVE-2008-3114)

    All users of java-1.6.0-ibm are advised to upgrade to these updated packages, containing the IBM 1.6.0 SR2 Java release, which resolves these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-3103
    CVE-2008-3104
    CVE-2008-3105
    CVE-2008-3106
    CVE-2008-3109
    CVE-2008-3110
    CVE-2008-3112
    CVE-2008-3114
    RHSA-2008:0906-01
    Platform(s):Supplementary for Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux 5 is installed
  • AND Package Information
  • java-1.6.0-ibm is earlier than 1:1.6.0.2-1jpp.2.el5
  • AND java-1.6.0-ibm is signed with Red Hat redhatrelease key
  • OR
  • java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.2-1jpp.2.el5
  • AND java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key
  • OR
  • java-1.6.0-ibm-demo is earlier than 1:1.6.0.2-1jpp.2.el5
  • AND java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key
  • OR
  • java-1.6.0-ibm-devel is earlier than 1:1.6.0.2-1jpp.2.el5
  • AND java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key
  • OR
  • java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.2-1jpp.2.el5
  • AND java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key
  • OR
  • java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.2-1jpp.2.el5
  • AND java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key
  • OR
  • java-1.6.0-ibm-plugin is earlier than 1:1.6.0.2-1jpp.2.el5
  • AND java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key
  • OR
  • java-1.6.0-ibm-src is earlier than 1:1.6.0.2-1jpp.2.el5
  • AND java-1.6.0-ibm-src is signed with Red Hat redhatrelease key
  • BACK