java-1.6.0-sun
87
A flaw in the JRE with passing arrays to the X11GraphicsDevice API was found. An untrusted
applet or application could use this flaw to access and modify the list of supported graphics
configurations. This flaw could also lead to sensitive information being leaked to unprivileged code.
(
CVE-2009-3879
555
)
It was discovered that the JRE passed entire objects to the logging API. This could lead to sensitive
information being leaked to either untrusted or lower-privileged code from an attacker-controlled applet
which has access to the logging API and is therefore able to manipulate (read and/or call) the passed
objects. (
CVE-2009-3880
556
)
Potential information leaks were found in various mutable static variables. These could be exploited in
application scenarios that execute untrusted scripting code. (
CVE-2009-3882
557
,
CVE-2009-3883
558
)
An information leak was found in the way the TimeZone.getTimeZone method was handled. This
method could load time zone files that are outside of the [JRE_HOME]/lib/zi/ directory, allowing a
remote attacker to probe the local file system. (
CVE-2009-3884
559
)
Note: The flaws concerning applets in this advisory,
CVE-2009-3869
560
,
CVE-2009-3871
561
,
CVE-2009-3873
562
,
CVE-2009-3874
563
,
CVE-2009-3879
564
,
CVE-2009-3880
565
,
CVE-2009-3881
566
and
CVE-2009-3884
567
, can only be triggered in java-1.6.0-openjdk by calling the "appletviewer"
application.
All users of java-1.6.0-openjdk are advised to upgrade to these updated packages, which resolve
these issues. All running instances of OpenJDK Java must be restarted for the update to take effect.
1.86. java-1.6.0-sun
1.86.1. RHBA-2010:0072: bug fix update
Note
This update has already been released (prior to the GA of this release) as errata
RHBA-2010:0072
568
Updated java-1.6.0-sun packages are now available for Red Hat Enterprise Linux 5.4 Supplementary.
The java-1.6.0-sun packages include the Sun Java 6 Runtime Environment, Sun Java 6 Software
Development Kit (SDK), the source code for the Sun Java class libraries, the Sun Java browser plug-
in and Web Start, the Sun JDBC/ODBC bridge driver, and demonstration files for the Sun Java 6 SDK.
555
https://www.redhat.com/security/data/cve/CVE-2009-3879.html
556
https://www.redhat.com/security/data/cve/CVE-2009-3880.html
557
https://www.redhat.com/security/data/cve/CVE-2009-3882.html
558
https://www.redhat.com/security/data/cve/CVE-2009-3883.html
559
https://www.redhat.com/security/data/cve/CVE-2009-3884.html
560
https://www.redhat.com/security/data/cve/CVE-2009-3869.html
561
https://www.redhat.com/security/data/cve/CVE-2009-3871.html
562
https://www.redhat.com/security/data/cve/CVE-2009-3873.html
563
https://www.redhat.com/security/data/cve/CVE-2009-3874.html
564
https://www.redhat.com/security/data/cve/CVE-2009-3879.html
565
https://www.redhat.com/security/data/cve/CVE-2009-3880.html
566
https://www.redhat.com/security/data/cve/CVE-2009-3881.html
567
https://www.redhat.com/security/data/cve/CVE-2009-3884.html
Summary of Contents for ENTERPRISE LINUX 5.5 - S 2010
Page 10: ...x ...
Page 308: ...298 ...
Page 310: ...300 ...
Page 468: ...458 ...
Page 470: ...460 ...