Fedora 9 : java-1.6.0-openjdk-1.6.0.0-0.16.b09.fc9 (2008-6439)

medium Nessus Plugin ID 33520

Synopsis

The remote Fedora host is missing a security update.

Description

- Tue Jul 8 2008 Lillian Angel <langel at redhat.com> - 1:1.6.0-0.16.b09

- Only apply hotspot security patch of jitarches.

- Wed Jul 2 2008 Lillian Angel <langel at redhat.com> - 1:1.6.0-0.16.b09

- Added OpenJDK security patches.

- Sat Jun 7 2008 Tom 'spot' Callaway <tcallawa at redhat.com> - 1:1.6.0-0.16.b09

- enable sparc/sparc64 builds

- Sat May 31 2008 Thomas Fitzsimmons <fitzsim at redhat.com> - 1:1.6.0.0-0.15.b09

- Fix keytool location passed to generate-cacerts.pl.

- Fri May 30 2008 Thomas Fitzsimmons <fitzsim at redhat.com> - 1:1.6.0.0-0.15.b09

- Generate cacerts file.

- Fri May 30 2008 Thomas Fitzsimmons <fitzsim at redhat.com> - 1:1.6.0.0-0.15.b09

- Remove jhat patch.

- Fri May 30 2008 Thomas Fitzsimmons <fitzsim at redhat.com> - 1:1.6.0.0-0.15.b09

- Remove makefile patch.

- Update generate-fedora-zip.sh.

- Fri May 30 2008 Thomas Fitzsimmons <fitzsim at redhat.com> - 1:1.6.0.0-0.15.b09

- Formatting cleanups.

- Fri May 30 2008 Thomas Fitzsimmons <fitzsim at redhat.com> - 1:1.6.0.0-0.15.b09

- Group all Mauve commands.

- Fri May 30 2008 Thomas Fitzsimmons <fitzsim at redhat.com> - 1:1.6.0.0-0.15.b09

- Formatting cleanups.

- Add jtreg_output to src subpackage.

- Wed May 28 2008 Lillian Angel <langel at redhat.com> - 1:1.6.0.0-0.15.b09

- Updated icedteasnapshot for new release.

- Tue May 27 2008 Thomas Fitzsimmons <fitzsim at redhat.com> - 1:1.6.0.0-0.15.b09

- Require ca-certificates.

- Symlink to ca-certificates cacerts.

- Remove cacerts from files list.

- Resolves: rhbz#444260

- Mon May 26 2008 Lillian Angel <langel at redhat.com> - 1:1.6.0.0-0.14.b09

- Added eclipse-ecj build requirement for mauve.

- Updated icedteasnapshot.

- Fri May 23 2008 Lillian Angel <langel at redhat.com> - 1:1.6.0.0-0.14.b09

- Fixed jtreg testing.

- Fri May 23 2008 Lillian Angel <langel at redhat.com> - 1:1.6.0.0-0.14.b09

- Updated icedteasnapshot.

- Updated release.

- Added jtreg testing.

- Thu May 22 2008 Lillian Angel <langel at redhat.com> - 1:1.6.0.0-0.13.b09

- Added new patch java-1.6.0-openjdk-java-access-bridge-tck.patch.

- Updated release.

- Mon May 5 2008 Lillian Angel <langel at redhat.com> - 1:1.6.0.0-0.12.b09

- Updated release.

- Updated icedteasnapshot.

- Resolves: rhbz#445182

- Resolves: rhbz#445183

- Tue Apr 29 2008 Lillian Angel <langel at redhat.com> - 1:1.6.0.0-0.11.b09

- Fixed javaws.desktop installation.

- Tue Apr 29 2008 Lillian Angel <langel at redhat.com> - 1:1.6.0.0-0.11.b09

- Updated icedteasnapshot.

[plus 6 lines in the Changelog]

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected java-1.6.0-openjdk package.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=452649

https://bugzilla.redhat.com/show_bug.cgi?id=452652

https://bugzilla.redhat.com/show_bug.cgi?id=452658

https://bugzilla.redhat.com/show_bug.cgi?id=452659

http://www.nessus.org/u?06539bb6

Plugin Details

Severity: Medium

ID: 33520

File Name: fedora_2008-6439.nasl

Version: 1.15

Type: local

Agent: unix

Published: 7/16/2008

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:java-1.6.0-openjdk, cpe:/o:fedoraproject:fedora:9

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 7/15/2008

Vulnerability Publication Date: 7/15/2008

Reference Information

BID: 30141, 30143, 30146

FEDORA: 2008-6439