RHEL 4 / 5 : java-1.6.0-ibm (RHSA-2009:0015)

critical Nessus Plugin ID 40737

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

Updated java-1.6.0-ibm packages that fix several security issues are now available for Red Hat Enterprise Linux 4 Extras and 5 Supplementary.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

The IBM 1.6.0 Java release includes the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit. These are summarized in the 'Security Alerts' from IBM.

All users of java-1.6.0-ibm are advised to upgrade to these updated packages, containing the IBM 1.6.0 SR3 Java release.

Solution

Update the affected packages.

See Also

https://access.redhat.com/security/cve/cve-2008-5347

https://access.redhat.com/security/cve/cve-2008-5348

https://access.redhat.com/security/cve/cve-2008-5350

https://access.redhat.com/security/cve/cve-2008-5352

https://access.redhat.com/security/cve/cve-2008-5353

https://access.redhat.com/security/cve/cve-2008-5354

https://access.redhat.com/security/cve/cve-2008-5359

https://access.redhat.com/security/cve/cve-2008-5360

https://www.ibm.com/us-en/?ar=1

https://access.redhat.com/errata/RHSA-2009:0015

https://access.redhat.com/security/cve/cve-2008-2086

https://access.redhat.com/security/cve/cve-2008-5339

https://access.redhat.com/security/cve/cve-2008-5344

https://access.redhat.com/security/cve/cve-2008-5345

Plugin Details

Severity: Critical

ID: 40737

File Name: redhat-RHSA-2009-0015.nasl

Version: 1.30

Type: local

Agent: unix

Published: 8/24/2009

Updated: 1/14/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-accessibility, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-demo, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-devel, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-javacomm, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-jdbc, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-plugin, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-src, cpe:/o:redhat:enterprise_linux:4, cpe:/o:redhat:enterprise_linux:4.7, cpe:/o:redhat:enterprise_linux:5, cpe:/o:redhat:enterprise_linux:5.2

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/13/2009

Vulnerability Publication Date: 12/4/2008

Exploitable With

CANVAS (CANVAS)

Core Impact

Metasploit (Sun Java Calendar Deserialization Privilege Escalation)

Reference Information

CVE: CVE-2008-2086, CVE-2008-5339, CVE-2008-5344, CVE-2008-5345, CVE-2008-5347, CVE-2008-5348, CVE-2008-5350, CVE-2008-5352, CVE-2008-5353, CVE-2008-5354, CVE-2008-5359, CVE-2008-5360

BID: 32608, 32620

CWE: 119, 189, 200, 264, 94

RHSA: 2009:0015