SuSE 10 Security Update : IBM Java 1.6.0 (ZYPP Patch Number 8383) (ROBOT)

critical Nessus Plugin ID 63092

Synopsis

The remote SuSE 10 host is missing a security-related patch.

Description

IBM Java 1.6.0 has been updated to SR12 which fixes bugs and security issues.

More information can be found on :

http://www.ibm.com/developerworks/java/jdk/alerts/

CVEs fixed: CVE-2012-3159 / CVE-2012-3216 / CVE-2012-5068 / CVE-2012-3143 / CVE-2012-5073 / CVE-2012-5075 / CVE-2012-5083 / CVE-2012-5083 / CVE-2012-5072 / CVE-2012-1531 / CVE-2012-5081 / CVE-2012-1532 / CVE-2012-1533 / CVE-2012-5069 / CVE-2012-5071 / CVE-2012-5084 / CVE-2012-5079 / CVE-2012-5089

Solution

Apply ZYPP patch number 8383.

See Also

http://support.novell.com/security/cve/CVE-2012-1531.html

http://support.novell.com/security/cve/CVE-2012-1532.html

http://support.novell.com/security/cve/CVE-2012-1533.html

http://support.novell.com/security/cve/CVE-2012-3143.html

http://support.novell.com/security/cve/CVE-2012-3159.html

http://support.novell.com/security/cve/CVE-2012-3216.html

http://support.novell.com/security/cve/CVE-2012-5068.html

http://support.novell.com/security/cve/CVE-2012-5069.html

http://support.novell.com/security/cve/CVE-2012-5071.html

http://support.novell.com/security/cve/CVE-2012-5072.html

http://support.novell.com/security/cve/CVE-2012-5073.html

http://support.novell.com/security/cve/CVE-2012-5075.html

http://support.novell.com/security/cve/CVE-2012-5079.html

http://support.novell.com/security/cve/CVE-2012-5081.html

http://support.novell.com/security/cve/CVE-2012-5083.html

http://support.novell.com/security/cve/CVE-2012-5084.html

http://support.novell.com/security/cve/CVE-2012-5089.html

Plugin Details

Severity: Critical

ID: 63092

File Name: suse_java-1_6_0-ibm-8383.nasl

Version: 1.12

Type: local

Agent: unix

Published: 11/29/2012

Updated: 1/19/2021

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.0

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/o:suse:suse_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/26/2012

Vulnerability Publication Date: 10/16/2012

Exploitable With

Metasploit (Sun Java Web Start Double Quote Injection)

Reference Information

CVE: CVE-2012-1531, CVE-2012-1532, CVE-2012-1533, CVE-2012-3143, CVE-2012-3159, CVE-2012-3216, CVE-2012-5068, CVE-2012-5069, CVE-2012-5071, CVE-2012-5072, CVE-2012-5073, CVE-2012-5075, CVE-2012-5079, CVE-2012-5081, CVE-2012-5083, CVE-2012-5084, CVE-2012-5089