RHEL 4 / 5 : java-1.5.0-ibm (RHSA-2009:1236)

This script is Copyright (C) 2009-2014 Tenable Network Security, Inc.


Synopsis :

The remote Red Hat host is missing one or more security updates.

Description :

Updated java-1.5.0-ibm packages that fix several security issues are
now available for Red Hat Enterprise Linux 4 Extras and 5
Supplementary.

This update has been rated as having critical security impact by the
Red Hat Security Response Team.

The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment
and the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. These
vulnerabilities are summarized on the IBM 'Security alerts' page
listed in the References section. (CVE-2009-2625, CVE-2009-2670,
CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2675)

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.5.0 SR10 Java release. All running
instances of IBM Java must be restarted for this update to take
effect.

Note: The packages included in this update are identical to the
packages made available by RHEA-2009:1208 and RHEA-2009:1210 on the
13th of August 2009. These packages are being reissued as a Red Hat
Security Advisory as they fixed a number of security issues that were
not made public until after those errata were released. Since the
packages are identical, there is no need to install this update if
RHEA-2009:1208 or RHEA-2009:1210 has already been installed.

See also :

https://www.redhat.com/security/data/cve/CVE-2009-2625.html
https://www.redhat.com/security/data/cve/CVE-2009-2670.html
https://www.redhat.com/security/data/cve/CVE-2009-2671.html
https://www.redhat.com/security/data/cve/CVE-2009-2672.html
https://www.redhat.com/security/data/cve/CVE-2009-2673.html
https://www.redhat.com/security/data/cve/CVE-2009-2675.html
http://www.ibm.com/developerworks/java/jdk/alerts/
http://rhn.redhat.com/errata/RHSA-2009-1236.html

Solution :

Update the affected packages.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.4
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Red Hat Local Security Checks

Nessus Plugin ID: 40814 ()

Bugtraq ID: 35944
35958

CVE ID: CVE-2009-2625
CVE-2009-2670
CVE-2009-2671
CVE-2009-2672
CVE-2009-2673
CVE-2009-2675
CVE-2009-3403