RHEL 3 / 4 / 5 : java-1.4.2-ibm (RHSA-2008:0955)
Critical Nessus Plugin ID 40729
SynopsisThe remote Red Hat host is missing one or more security updates.
DescriptionUpdated java-1.4.2-ibm packages that fix several security issues are now available for Red Hat Enterprise Linux 3 Extras, Red Hat Enterprise Linux 4 Extras, and Red Hat Enterprise Linux 5 Supplementary.
This update has been rated as having critical security impact by the Red Hat Security Response Team.
IBM's 1.4.2 SR12 Java release includes the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit.
Multiple vulnerabilities with unsigned applets were reported. A remote attacker could misuse an unsigned applet to connect to localhost services running on the host running the applet. (CVE-2008-3104)
Two file processing vulnerabilities in Java Web Start were found.
Using an untrusted Java Web Start application, a remote attacker was able to create or delete arbitrary files with the permissions of the user running the untrusted application. (CVE-2008-3112, CVE-2008-3113)
A vulnerability in Java Web Start when processing untrusted applications was reported. An attacker was able to acquire sensitive information, such as the cache location. (CVE-2008-3114)
All users of java-1.4.2-ibm are advised to upgrade to these updated packages, which contain IBM's 1.4.2 SR12 Java release which resolves these issues.
SolutionUpdate the affected packages.