RHEL 4 / 5 : java-1.6.0-sun (RHSA-2009:1200)

This script is Copyright (C) 2009-2014 Tenable Network Security, Inc.


Synopsis :

The remote Red Hat host is missing one or more security updates.

Description :

Updated java-1.6.0-sun packages that correct several security issues
are now available for Red Hat Enterprise Linux 4 Extras and 5
Supplementary.

This update has been rated as having critical security impact by the
Red Hat Security Response Team.

The Sun 1.6.0 Java release includes the Sun Java 6 Runtime Environment
and the Sun Java 6 Software Development Kit.

This update fixes several vulnerabilities in the Sun Java 6 Runtime
Environment and the Sun Java 6 Software Development Kit. These
vulnerabilities are summarized on the 'Advance notification of
Security Updates for Java SE' page from Sun Microsystems, listed in
the References section. (CVE-2009-0217, CVE-2009-2475, CVE-2009-2476,
CVE-2009-2625, CVE-2009-2670, CVE-2009-2671, CVE-2009-2672,
CVE-2009-2673, CVE-2009-2674, CVE-2009-2675, CVE-2009-2676,
CVE-2009-2690)

Users of java-1.6.0-sun should upgrade to these updated packages,
which correct these issues. All running instances of Sun Java must be
restarted for the update to take effect.

See also :

https://www.redhat.com/security/data/cve/CVE-2009-0217.html
https://www.redhat.com/security/data/cve/CVE-2009-2475.html
https://www.redhat.com/security/data/cve/CVE-2009-2476.html
https://www.redhat.com/security/data/cve/CVE-2009-2625.html
https://www.redhat.com/security/data/cve/CVE-2009-2670.html
https://www.redhat.com/security/data/cve/CVE-2009-2671.html
https://www.redhat.com/security/data/cve/CVE-2009-2672.html
https://www.redhat.com/security/data/cve/CVE-2009-2673.html
https://www.redhat.com/security/data/cve/CVE-2009-2674.html
https://www.redhat.com/security/data/cve/CVE-2009-2675.html
https://www.redhat.com/security/data/cve/CVE-2009-2676.html
https://www.redhat.com/security/data/cve/CVE-2009-2690.html
https://www.redhat.com/security/data/cve/CVE-2009-2716.html
https://www.redhat.com/security/data/cve/CVE-2009-2718.html
https://www.redhat.com/security/data/cve/CVE-2009-2719.html
https://www.redhat.com/security/data/cve/CVE-2009-2720.html
http://www.nessus.org/u?d520449c
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1
http://rhn.redhat.com/errata/RHSA-2009-1200.html

Solution :

Update the affected packages.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.4
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false