Oval Definition:oval:com.redhat.rhsa:def:20130605
Revision Date:2013-03-06Version:636
Title:RHSA-2013:0605: java-1.6.0-openjdk security update (Critical)
Description:These packages provide the OpenJDK 6 Java Runtime Environment and the OpenJDK 6 Software Development Kit.

  • An integer overflow flaw was found in the way the 2D component handled certain sample model instances. A specially-crafted sample model instance could cause Java Virtual Machine memory corruption and, possibly, lead to arbitrary code execution with virtual machine privileges. (CVE-2013-0809)

  • It was discovered that the 2D component did not properly reject certain malformed images. Specially-crafted raster parameters could cause Java Virtual Machine memory corruption and, possibly, lead to arbitrary code execution with virtual machine privileges. (CVE-2013-1493)

    Note: If your system has not yet been upgraded to Red Hat Enterprise Linux 6.4 and the web browser plug-in provided by the icedtea-web package was installed, the issues exposed via Java applets could have been exploited without user interaction if a user visited a malicious website. Thus, this update has been rated as having critical security impact as a one time exception. The icedtea-web package as provided with Red Hat Enterprise Linux 6.4 uses OpenJDK 7 instead.

    This erratum also upgrades the OpenJDK package to IcedTea6 1.11.9. Refer to the NEWS file, linked to in the References, for further information.

    All users of java-1.6.0-openjdk are advised to upgrade to these updated packages, which resolve these issues. All running instances of OpenJDK Java must be restarted for the update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2013-0809
    CVE-2013-0809
    CVE-2013-1493
    CVE-2013-1493
    RHSA-2013:0605
    RHSA-2013:0605-02
    RHSA-2013:0605-02
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4
  • AND java-1.6.0-openjdk is signed with Red Hat redhatrelease2 key
  • java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4
  • AND java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease2 key
  • java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4
  • AND java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease2 key
  • java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4
  • AND java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease2 key
  • java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4
  • AND java-1.6.0-openjdk-src is signed with Red Hat redhatrelease2 key
  • BACK