RHEL 6 : java-1.7.1-ibm (RHSA-2018:1974)

Medium Nessus Plugin ID 110692

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

An update for java-1.7.1-ibm is now available for Red Hat Satellite 5.6 and Red Hat Satellite 5.7.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

IBM Java SE version 7 Release 1 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit.

This update upgrades IBM Java SE 7 to version 7R1 SR4-FP25.

Security Fix(es) :

* OpenJDK: unrestricted deserialization of data from JCEKS key stores (Security, 8189997) (CVE-2018-2794)

* Oracle JDK: unspecified vulnerability fixed in 6u191, 7u171, and 8u161 (Security) (CVE-2018-2783)

* OpenJDK: insufficient consistency checks in deserialization of multiple classes (Security, 8189977) (CVE-2018-2795)

* OpenJDK: unbounded memory allocation during deserialization in PriorityBlockingQueue (Concurrency, 8189981) (CVE-2018-2796)

* OpenJDK: unbounded memory allocation during deserialization in TabularDataSupport (JMX, 8189985) (CVE-2018-2797)

* OpenJDK: unbounded memory allocation during deserialization in Container (AWT, 8189989) (CVE-2018-2798)

* OpenJDK: unbounded memory allocation during deserialization in NamedNodeMapImpl (JAXP, 8189993) (CVE-2018-2799)

* OpenJDK: RMI HTTP transport enabled by default (RMI, 8193833) (CVE-2018-2800)

* OpenJDK: incorrect merging of sections in the JAR manifest (Security, 8189969) (CVE-2018-2790)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Update the affected java-1.7.1-ibm and / or java-1.7.1-ibm-devel packages.

See Also

http://rhn.redhat.com/errata/RHSA-2018-1974.html

https://www.redhat.com/security/data/cve/CVE-2018-2783.html

https://www.redhat.com/security/data/cve/CVE-2018-2790.html

https://www.redhat.com/security/data/cve/CVE-2018-2794.html

https://www.redhat.com/security/data/cve/CVE-2018-2795.html

https://www.redhat.com/security/data/cve/CVE-2018-2796.html

https://www.redhat.com/security/data/cve/CVE-2018-2797.html

https://www.redhat.com/security/data/cve/CVE-2018-2798.html

https://www.redhat.com/security/data/cve/CVE-2018-2799.html

https://www.redhat.com/security/data/cve/CVE-2018-2800.html

Plugin Details

Severity: Medium

ID: 110692

File Name: redhat-RHSA-2018-1974.nasl

Version: 1.2

Type: local

Agent: unix

Published: 2018/06/26

Modified: 2018/09/07

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 5.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSSv3

Base Score: 7.7

Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:java-1.7.1-ibm, p-cpe:/a:redhat:enterprise_linux:java-1.7.1-ibm-devel, cpe:/o:redhat:enterprise_linux:6

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 2018/06/25

Reference Information

CVE: CVE-2018-2783, CVE-2018-2790, CVE-2018-2794, CVE-2018-2795, CVE-2018-2796, CVE-2018-2797, CVE-2018-2798, CVE-2018-2799, CVE-2018-2800

RHSA: 2018:1974