openSUSE Security Update : java-1_6_0-openjdk (openSUSE-SU-2010:0957-1)

This script is Copyright (C) 2014 Tenable Network Security, Inc.


Synopsis :

The remote openSUSE host is missing a security update.

Description :

Icedtea included in java-1_6_0-openjdk was updated to version
1.7.5/1.8.2/1.9.1 to fix several security issues :

- S6914943, CVE-2009-3555: TLS: MITM attacks via session
renegotiation

- S6559775, CVE-2010-3568: OpenJDK Deserialization Race
condition

- S6891766, CVE-2010-3554: OpenJDK corba reflection
vulnerabilities

- S6925710, CVE-2010-3562: OpenJDK IndexColorModel
double-free

- S6938813, CVE-2010-3557: OpenJDK Swing mutable static

- S6957564, CVE-2010-3548: OpenJDK DNS server IP address
information leak

- S6958060, CVE-2010-3564: OpenJDK kerberos vulnerability

- S6963023, CVE-2010-3565: OpenJDK JPEG writeImage remote
code execution

- S6963489, CVE-2010-3566: OpenJDK ICC Profile remote code
execution

- S6966692, CVE-2010-3569: OpenJDK Serialization
inconsistencies

- S6622002, CVE-2010-3553: UIDefault.ProxyLazyValue has
unsafe reflection usage

- S6925672, CVE-2010-3561: Privileged ServerSocket.accept
allows receiving connections from any host

- S6952017, CVE-2010-3549: HttpURLConnection chunked
encoding issue (Http request splitting)

- S6952603, CVE-2010-3551: NetworkInterface reveals local
network address to untrusted code

- S6961084, CVE-2010-3541: limit setting of some request
headers in HttpURLConnection

- S6963285, CVE-2010-3567: Crash in ICU Opentype layout
engine due to mismatch in character counts

- S6980004, CVE-2010-3573: limit HTTP request cookie
headers in HttpURLConnection

- S6981426, CVE-2010-3574: limit use of TRACE method in
HttpURLConnection

See also :

http://lists.opensuse.org/opensuse-updates/2010-11/msg00024.html
https://bugzilla.novell.com/show_bug.cgi?id=642531

Solution :

Update the affected java-1_6_0-openjdk packages.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
Public Exploit Available : true

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now