RHSA-2009:0377: Important security update
107
An integer overflow flaw was found in the way the JRE processes JPEG images. An untrusted
application could use this flaw to extend its privileges, allowing it to read and write local files,
as well as to execute local applications with the privileges of the user running the application.
(
CVE-2009-2674
698
)
An integer overflow flaw was found in the JRE unpack200 functionality. An untrusted applet or
application could extend its privileges, allowing it to read and write local files, as well as to execute
local applications with the privileges of the user running the applet or application. (
CVE-2009-2675
699
)
It was discovered that JDK13Services grants unnecessary privileges to certain object types. This
could be misused by an untrusted applet or application to use otherwise restricted functionality.
(
CVE-2009-2689
700
)
An information disclosure flaw was found in the way private Java variables were handled. An untrusted
applet or application could use this flaw to obtain information from variables that would otherwise be
private. (
CVE-2009-2690
701
)
Note: The flaws concerning applets in this advisory, CVE-2009-2475, CVE-2009-2670,
CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2675, CVE-2009-2689, and
CVE-2009-2690, can only be triggered in java-1.6.0-openjdk by calling the "appletviewer" application.
This update also fixes the following bug:
• the EVR in the java-1.6.0-openjdk package as shipped with Red Hat Enterprise Linux allowed the
java-1.6.0-openjdk package from the EPEL repository to take precedence (appear newer). Users
using java-1.6.0-openjdk from EPEL would not have received security updates since October 2008.
This update prevents the packages from EPEL from taking precedence. (
BZ#499079
702
)
All users of java-1.6.0-openjdk are advised to upgrade to these updated packages, which resolve
these issues. All running instances of OpenJDK Java must be restarted for the update to take effect.
1.103.2. RHSA-2009:0377: Important security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:0377
703
Updated java-1.6.0-openjdk packages that fix several security issues are now available for Red Hat
Enterprise Linux 5.
This update has been rated as having important security impact by the Red Hat Security Response
Team.
These packages provide the OpenJDK 6 Java Runtime Environment and the OpenJDK 6 Software
Development Kit. The Java Runtime Environment (JRE) contains the software and tools that users
need to run applications written using the Java programming language.
698
https://www.redhat.com/security/data/cve/CVE-2009-2674.html
699
https://www.redhat.com/security/data/cve/CVE-2009-2675.html
700
https://www.redhat.com/security/data/cve/CVE-2009-2689.html
701
https://www.redhat.com/security/data/cve/CVE-2009-2690.html
Содержание ENTERPRISE 5.4 RELEASE NOTES
Страница 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Страница 18: ...xviii ...
Страница 306: ...288 ...
Страница 464: ...446 ...
Страница 466: ...448 ...