Oval Definition:oval:com.redhat.rhsa:def:20100130
Revision Date:2010-03-03Version:602
Title:RHSA-2010:0130: java-1.5.0-ibm security update (Moderate)
Description:The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit.

  • A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure Sockets Layer) protocols handle session renegotiation. A man-in-the-middle attacker could use this flaw to prefix arbitrary plain text to a client's session (for example, an HTTPS connection to a website). This could force the server to process an attacker's request as if authenticated using the victim's credentials. (CVE-2009-3555)

    This update disables renegotiation in the Java Secure Socket Extension (JSSE) component. Unsafe renegotiation can be re-enabled using the com.ibm.jsse2.renegotiate property. Refer to the following Knowledgebase article for details: http://kbase.redhat.com/faq/docs/DOC-20491

    All users of java-1.5.0-ibm are advised to upgrade to these updated packages, containing the IBM 1.5.0 SR11-FP1 Java release. All running instances of IBM Java must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-3555
    CVE-2010-0084
    CVE-2010-0085
    CVE-2010-0087
    CVE-2010-0088
    CVE-2010-0089
    CVE-2010-0091
    CVE-2010-0092
    CVE-2010-0094
    CVE-2010-0095
    CVE-2010-0837
    CVE-2010-0838
    CVE-2010-0839
    RHSA-2010:0130-01
    Platform(s):Supplementary for Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux 5 is installed
  • AND Package Information
  • java-1.5.0-ibm is earlier than 1:1.5.0.11.1-1jpp.3.el5
  • AND java-1.5.0-ibm is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.11.1-1jpp.3.el5
  • AND java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-ibm-demo is earlier than 1:1.5.0.11.1-1jpp.3.el5
  • AND java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-ibm-devel is earlier than 1:1.5.0.11.1-1jpp.3.el5
  • AND java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.11.1-1jpp.3.el5
  • AND java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.11.1-1jpp.3.el5
  • AND java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-ibm-plugin is earlier than 1:1.5.0.11.1-1jpp.3.el5
  • AND java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key
  • OR
  • java-1.5.0-ibm-src is earlier than 1:1.5.0.11.1-1jpp.3.el5
  • AND java-1.5.0-ibm-src is signed with Red Hat redhatrelease key
  • BACK