Oval Definition:oval:com.redhat.rhsa:def:20080955
Revision Date:2008-11-25Version:602
Title:RHSA-2008:0955: java-1.4.2-ibm security update (Critical)
Description:IBM's 1.4.2 SR12 Java release includes the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit.

  • Multiple vulnerabilities with unsigned applets were reported. A remote attacker could misuse an unsigned applet to connect to localhost services running on the host running the applet. (CVE-2008-3104)

  • Two file processing vulnerabilities in Java Web Start were found. Using an untrusted Java Web Start application, a remote attacker was able to create or delete arbitrary files with the permissions of the user running the untrusted application. (CVE-2008-3112, CVE-2008-3113)

  • A vulnerability in Java Web Start when processing untrusted applications was reported. An attacker was able to acquire sensitive information, such as the cache location. (CVE-2008-3114)

    All users of java-1.4.2-ibm are advised to upgrade to these updated packages, which contain IBM's 1.4.2 SR12 Java release which resolves these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-3104
    CVE-2008-3112
    CVE-2008-3113
    CVE-2008-3114
    RHSA-2008:0955-01
    Platform(s):Supplementary for Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux 5 is installed
  • AND Package Information
  • java-1.4.2-ibm is earlier than 0:1.4.2.12-1jpp.1.el5
  • AND java-1.4.2-ibm is signed with Red Hat redhatrelease key
  • OR
  • java-1.4.2-ibm-demo is earlier than 0:1.4.2.12-1jpp.1.el5
  • AND java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key
  • OR
  • java-1.4.2-ibm-devel is earlier than 0:1.4.2.12-1jpp.1.el5
  • AND java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key
  • OR
  • java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.12-1jpp.1.el5
  • AND java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key
  • OR
  • java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.12-1jpp.1.el5
  • AND java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key
  • OR
  • java-1.4.2-ibm-plugin is earlier than 0:1.4.2.12-1jpp.1.el5
  • AND java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key
  • OR
  • java-1.4.2-ibm-src is earlier than 0:1.4.2.12-1jpp.1.el5
  • AND java-1.4.2-ibm-src is signed with Red Hat redhatrelease key
  • BACK