Chapter 1. Package Updates
108
A flaw was found in the way that the Java Virtual Machine (JVM) handled temporary font files. A
malicious applet could use this flaw to use large amounts of disk space, causing a denial of service.
(
CVE-2006-2426
704
)
A memory leak flaw was found in LittleCMS (embedded in OpenJDK). An application using color
profiles could use excessive amounts of memory, and possibly crash after using all available memory,
if used to open specially-crafted images. (
CVE-2009-0581
705
)
Multiple integer overflow flaws which could lead to heap-based buffer overflows, as well as multiple
insufficient input validation flaws, were found in the way LittleCMS handled color profiles. An attacker
could use these flaws to create a specially-crafted image file which could cause a Java application to
crash or, possibly, execute arbitrary code when opened. (
CVE-2009-0723
706
,
CVE-2009-0733
707
)
A null pointer dereference flaw was found in LittleCMS. An application using color profiles could crash
while converting a specially-crafted image file. (
CVE-2009-0793
708
)
A flaw in the Java API for XML Web Services (JAX-WS) service endpoint handling could allow a
remote attacker to cause a denial of service on the server application hosting the JAX-WS service
endpoint. (
CVE-2009-1101
709
)
A flaw in the way the Java Runtime Environment initialized LDAP connections could allow a remote,
authenticated user to cause a denial of service on the LDAP service. (
CVE-2009-1093
710
)
A flaw in the Java Runtime Environment LDAP client could allow malicious data from an LDAP server
to cause arbitrary code to be loaded and then run on an LDAP client. (
CVE-2009-1094
711
)
Several buffer overflow flaws were found in the Java Runtime Environment unpack200 functionality.
An untrusted applet could extend its privileges, allowing it to read and write local files, as well as
to execute local applications with the privileges of the user running the applet. (
CVE-2009-1095
712
,
CVE-2009-1096
713
)
A flaw in the Java Runtime Environment Virtual Machine code generation functionality could allow
untrusted applets to extend their privileges. An untrusted applet could extend its privileges, allowing it
to read and write local files, as well as execute local applications with the privileges of the user running
the applet. (
CVE-2009-1102
714
)
A buffer overflow flaw was found in the splash screen processing. A remote attacker could extend
privileges to read and write local files, as well as to execute local applications with the privileges of the
user running the java process. (
CVE-2009-1097
715
)
A buffer overflow flaw was found in how GIF images were processed. A remote attacker could extend
privileges to read and write local files, as well as execute local applications with the privileges of the
user running the java process. (
CVE-2009-1098
716
)
704
https://www.redhat.com/security/data/cve/CVE-2006-2426.html
705
https://www.redhat.com/security/data/cve/CVE-2009-0581.html
706
https://www.redhat.com/security/data/cve/CVE-2009-0723.html
707
https://www.redhat.com/security/data/cve/CVE-2009-0733.html
708
https://www.redhat.com/security/data/cve/CVE-2009-0793.html
709
https://www.redhat.com/security/data/cve/CVE-2009-1101.html
710
https://www.redhat.com/security/data/cve/CVE-2009-1093.html
711
https://www.redhat.com/security/data/cve/CVE-2009-1094.html
712
https://www.redhat.com/security/data/cve/CVE-2009-1095.html
713
https://www.redhat.com/security/data/cve/CVE-2009-1096.html
714
https://www.redhat.com/security/data/cve/CVE-2009-1102.html
715
https://www.redhat.com/security/data/cve/CVE-2009-1097.html
716
https://www.redhat.com/security/data/cve/CVE-2009-1098.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...