openSUSE Security Update : java-1_6_0-openjdk (openSUSE-SU-2010:0957-1)

This script is Copyright (C) 2011-2014 Tenable Network Security, Inc.

Synopsis :

The remote openSUSE host is missing a security update.

Description :

Icedtea included in java-1_6_0-openjdk was updated to version
1.7.5/1.8.2/1.9.1 to fix several security issues :

- S6914943, CVE-2009-3555: TLS: MITM attacks via session

- S6559775, CVE-2010-3568: OpenJDK Deserialization Race

- S6891766, CVE-2010-3554: OpenJDK corba reflection

- S6925710, CVE-2010-3562: OpenJDK IndexColorModel

- S6938813, CVE-2010-3557: OpenJDK Swing mutable static

- S6957564, CVE-2010-3548: OpenJDK DNS server IP address
information leak

- S6958060, CVE-2010-3564: OpenJDK kerberos vulnerability

- S6963023, CVE-2010-3565: OpenJDK JPEG writeImage remote
code execution

- S6963489, CVE-2010-3566: OpenJDK ICC Profile remote code

- S6966692, CVE-2010-3569: OpenJDK Serialization

- S6622002, CVE-2010-3553: UIDefault.ProxyLazyValue has
unsafe reflection usage

- S6925672, CVE-2010-3561: Privileged ServerSocket.accept
allows receiving connections from any host

- S6952017, CVE-2010-3549: HttpURLConnection chunked
encoding issue (Http request splitting)

- S6952603, CVE-2010-3551: NetworkInterface reveals local
network address to untrusted code

- S6961084, CVE-2010-3541: limit setting of some request
headers in HttpURLConnection

- S6963285, CVE-2010-3567: Crash in ICU Opentype layout
engine due to mismatch in character counts

- S6980004, CVE-2010-3573: limit HTTP request cookie
headers in HttpURLConnection

- S6981426, CVE-2010-3574: limit use of TRACE method in

See also :

Solution :

Update the affected java-1_6_0-openjdk packages.

Risk factor :

Critical / CVSS Base Score : 10.0
Public Exploit Available : true

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now