Oval Definition:oval:com.redhat.rhsa:def:20130273
Revision Date:2013-02-20Version:637
Title:RHSA-2013:0273: java-1.6.0-openjdk security update (Critical)
Description:These packages provide the OpenJDK 6 Java Runtime Environment and the OpenJDK 6 Software Development Kit.

  • An improper permission check issue was discovered in the JMX component in OpenJDK. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions. (CVE-2013-1486)

  • It was discovered that OpenJDK leaked timing information when decrypting TLS/SSL protocol encrypted records when CBC-mode cipher suites were used. A remote attacker could possibly use this flaw to retrieve plain text from the encrypted packets by using a TLS/SSL server as a padding oracle. (CVE-2013-0169)

    Note: If the web browser plug-in provided by the icedtea-web package was installed, CVE-2013-1486 could have been exploited without user interaction if a user visited a malicious website.

    This erratum also upgrades the OpenJDK package to IcedTea6 1.11.8. Refer to the NEWS file, linked to in the References, for further information.

    All users of java-1.6.0-openjdk are advised to upgrade to these updated packages, which resolve these issues. All running instances of OpenJDK Java must be restarted for the update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2013-0169
    CVE-2013-0169
    CVE-2013-1486
    CVE-2013-1486
    RHSA-2013:0273
    RHSA-2013:0273-01
    RHSA-2013:0273-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3
  • AND java-1.6.0-openjdk is signed with Red Hat redhatrelease2 key
  • java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3
  • AND java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease2 key
  • java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3
  • AND java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease2 key
  • java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3
  • AND java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease2 key
  • java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3
  • AND java-1.6.0-openjdk-src is signed with Red Hat redhatrelease2 key
  • BACK