Synopsis
The remote SuSE 10 host is missing a security-related patch.
Description
IBM Java 1.4.2 SR 13 Fixpack 10 has been released and fixes various bugs and security issues.
The following security issues have been fixed :
  - Unspecified vulnerability in the Java Runtime     Environment (JRE) component in Oracle Java SE 6 Update     25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31     and earlier allows remote untrusted Java Web Start     applications and untrusted Java applets to affect     integrity via unknown vectors related to     Deserialization. (CVE-2011-0865)
  - Unspecified vulnerability in the Java Runtime     Environment (JRE) component in Oracle Java SE 6 Update     25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31     and earlier, when running on Windows, allows remote     untrusted Java Web Start applications and untrusted Java     applets to affect confidentiality, integrity, and     availability via unknown vectors related to Java Runtime     Environment. (CVE-2011-0866)
  - Unspecified vulnerability in the Java Runtime     Environment (JRE) component in Oracle Java SE 6 Update     25 and earlier, when running on Windows, allows remote     untrusted Java Web Start applications and untrusted Java     applets to affect confidentiality, integrity, and     availability via unknown vectors related to Deployment,     a different vulnerability than CVE-2011-0786.
    (CVE-2011-0802)
  - Unspecified vulnerability in the Java Runtime     Environment (JRE) component in Oracle Java SE 6 Update     25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31     and earlier allows remote attackers to affect     confidentiality, integrity, and availability via unknown     vectors related to Sound, a different vulnerability than     CVE-2011-0802. (CVE-2011-0814)
  - Unspecified vulnerability in the Java Runtime     Environment (JRE) component in Oracle Java SE 6 Update     25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31     and earlier allows remote untrusted Java Web Start     applications and untrusted Java applets to affect     confidentiality, integrity, and availability via unknown     vectors related to AWT. (CVE-2011-0815)
  - Multiple unspecified vulnerabilities in the Java Runtime     Environment (JRE) component in Oracle Java SE 6 Update     25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31     and earlier allow remote attackers to affect     confidentiality, integrity, and availability via unknown     vectors related to 2D. (CVE-2011-0862)
  - Unspecified vulnerability in the Java Runtime     Environment (JRE) component in Oracle Java SE 6 Update     25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31     and earlier allows remote untrusted Java Web Start     applications and untrusted Java applets to affect     confidentiality via unknown vectors related to     Networking. (CVE-2011-0867)
  - Unspecified vulnerability in the Java Runtime     Environment (JRE) component in Oracle Java SE 6 Update     25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31     and earlier allows remote untrusted Java Web Start     applications and untrusted Java applets to affect     confidentiality, integrity, and availability via unknown     vectors related to Swing. (CVE-2011-0871)
  - Unspecified vulnerability in the Java Runtime     Environment (JRE) component in Oracle Java SE 6 Update     25 and earlier allows remote attackers to affect     availability via unknown vectors related to NIO.
    (CVE-2011-0872)
Solution
Apply ZYPP patch number 7698.
Plugin Details
File Name: suse_java-1_4_2-ibm-7698.nasl
Agent: unix
Supported Sensors: Nessus Agent, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Vulnerability Information
CPE: cpe:/o:suse:suse_linux
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: Exploits are available
Patch Publication Date: 8/18/2011