Security Advisory Critical: java-1.5.0-sun security update

Advisory: RHSA-2008:0123-4
Type: Security Advisory
Severity: Critical
Issued on: 2008-02-12
Last updated on: 2008-02-12
Affected Products: RHEL Desktop Supplementary (v. 5 client)
RHEL Supplementary (v. 5 server)
Red Hat Enterprise Linux Extras (v. 4)
OVAL: com.redhat.rhsa-20080123.xml
CVEs (cve.mitre.org): CVE-2008-0657

Details

Updated java-1.5.0-sun packages that correct several security issues are
now available for Red Hat Enterprise Linux 4 Extras and 5 Supplementary.

This update has been rated as having critical security impact by the Red
Hat Security Response Team.

The Java Runtime Environment (JRE) contains the software and tools that
users need to run applets and applications written using the Java
programming language.

These updated java-1.5.0-sun packages resolve the following security issues:

Two vulnerabilities in the Java Runtime Environment allowed an untrusted
application or applet to elevate the assigned privileges. This could be
misused by a malicious website to read and write local files or execute
local applications in the context of the user running the Java process.
(CVE-2008-0657)

Users of java-1.5.0-sun should upgrade to these updated packages, which
contain backported patches to correct these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

RHEL Desktop Supplementary (v. 5 client)

IA-32:
java-1.5.0-sun-1.5.0.14-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    e3ccf43ff7aece7ebcc22f6a06c30ac4
java-1.5.0-sun-demo-1.5.0.14-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    358ce4260cb4bef0a3c095ea65fcd7b7
java-1.5.0-sun-devel-1.5.0.14-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    94ef8907c114dfff36e7941dd6842946
java-1.5.0-sun-jdbc-1.5.0.14-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    2d127eed166c41edd631d5f41f5c6059
java-1.5.0-sun-plugin-1.5.0.14-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    46325c0dd1ecd514d2a07fbff00b2453
java-1.5.0-sun-src-1.5.0.14-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    937264c4c6c5bedd9d6f38de0be79ffa
 
x86_64:
java-1.5.0-sun-1.5.0.14-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    a6e310113f8c81112e4ec2dd64b97265
java-1.5.0-sun-demo-1.5.0.14-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    16cf61a225b52e3f2665d0767e514bbc
java-1.5.0-sun-devel-1.5.0.14-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    74511b10387b462c87a6433436558542
java-1.5.0-sun-jdbc-1.5.0.14-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    14a38c8c933369db923958e0303af8b5
java-1.5.0-sun-plugin-1.5.0.14-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    46325c0dd1ecd514d2a07fbff00b2453
java-1.5.0-sun-src-1.5.0.14-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    1ad6e6c1b20650e407d7fb4811ef7016
 
RHEL Supplementary (v. 5 server)

IA-32:
java-1.5.0-sun-1.5.0.14-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    e3ccf43ff7aece7ebcc22f6a06c30ac4
java-1.5.0-sun-demo-1.5.0.14-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    358ce4260cb4bef0a3c095ea65fcd7b7
java-1.5.0-sun-devel-1.5.0.14-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    94ef8907c114dfff36e7941dd6842946
java-1.5.0-sun-jdbc-1.5.0.14-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    2d127eed166c41edd631d5f41f5c6059
java-1.5.0-sun-plugin-1.5.0.14-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    46325c0dd1ecd514d2a07fbff00b2453
java-1.5.0-sun-src-1.5.0.14-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    937264c4c6c5bedd9d6f38de0be79ffa
 
x86_64:
java-1.5.0-sun-1.5.0.14-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    a6e310113f8c81112e4ec2dd64b97265
java-1.5.0-sun-demo-1.5.0.14-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    16cf61a225b52e3f2665d0767e514bbc
java-1.5.0-sun-devel-1.5.0.14-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    74511b10387b462c87a6433436558542
java-1.5.0-sun-jdbc-1.5.0.14-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    14a38c8c933369db923958e0303af8b5
java-1.5.0-sun-plugin-1.5.0.14-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    46325c0dd1ecd514d2a07fbff00b2453
java-1.5.0-sun-src-1.5.0.14-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    1ad6e6c1b20650e407d7fb4811ef7016
 
Red Hat Enterprise Linux Extras (v. 4)

IA-32:
java-1.5.0-sun-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    5ad46cb20bd83992aa6332a14e2bbe7c
java-1.5.0-sun-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    5ad46cb20bd83992aa6332a14e2bbe7c
java-1.5.0-sun-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    5ad46cb20bd83992aa6332a14e2bbe7c
java-1.5.0-sun-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    5ad46cb20bd83992aa6332a14e2bbe7c
java-1.5.0-sun-demo-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    740f3209e21282e35fa7f331bf2fcaea
java-1.5.0-sun-demo-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    740f3209e21282e35fa7f331bf2fcaea
java-1.5.0-sun-demo-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    740f3209e21282e35fa7f331bf2fcaea
java-1.5.0-sun-demo-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    740f3209e21282e35fa7f331bf2fcaea
java-1.5.0-sun-devel-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    f5a9b974c824a725edd6d3fc4c786f7f
java-1.5.0-sun-devel-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    f5a9b974c824a725edd6d3fc4c786f7f
java-1.5.0-sun-devel-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    f5a9b974c824a725edd6d3fc4c786f7f
java-1.5.0-sun-devel-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    f5a9b974c824a725edd6d3fc4c786f7f
java-1.5.0-sun-jdbc-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    87f2305ab87601118a776aa8f5c1b118
java-1.5.0-sun-jdbc-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    87f2305ab87601118a776aa8f5c1b118
java-1.5.0-sun-jdbc-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    87f2305ab87601118a776aa8f5c1b118
java-1.5.0-sun-jdbc-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    87f2305ab87601118a776aa8f5c1b118
java-1.5.0-sun-plugin-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    43aa8331142722c94de259e7f2613561
java-1.5.0-sun-plugin-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    43aa8331142722c94de259e7f2613561
java-1.5.0-sun-plugin-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    43aa8331142722c94de259e7f2613561
java-1.5.0-sun-plugin-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    43aa8331142722c94de259e7f2613561
java-1.5.0-sun-src-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    36da23dd98f181c5536fc0018fed725e
java-1.5.0-sun-src-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    36da23dd98f181c5536fc0018fed725e
java-1.5.0-sun-src-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    36da23dd98f181c5536fc0018fed725e
java-1.5.0-sun-src-1.5.0.14-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    36da23dd98f181c5536fc0018fed725e
 
x86_64:
java-1.5.0-sun-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    44015e971c10e9b14ea6b6123750bd54
java-1.5.0-sun-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    44015e971c10e9b14ea6b6123750bd54
java-1.5.0-sun-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    44015e971c10e9b14ea6b6123750bd54
java-1.5.0-sun-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    44015e971c10e9b14ea6b6123750bd54
java-1.5.0-sun-demo-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    497005d168d5de4ca8fb86c249e5a3a3
java-1.5.0-sun-demo-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    497005d168d5de4ca8fb86c249e5a3a3
java-1.5.0-sun-demo-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    497005d168d5de4ca8fb86c249e5a3a3
java-1.5.0-sun-demo-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    497005d168d5de4ca8fb86c249e5a3a3
java-1.5.0-sun-devel-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    6c4e2af8a95812b5f75bfd116f1b9b8b
java-1.5.0-sun-devel-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    6c4e2af8a95812b5f75bfd116f1b9b8b
java-1.5.0-sun-devel-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    6c4e2af8a95812b5f75bfd116f1b9b8b
java-1.5.0-sun-devel-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    6c4e2af8a95812b5f75bfd116f1b9b8b
java-1.5.0-sun-jdbc-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    4520a93c807cc135d0ca079a8d9d1127
java-1.5.0-sun-jdbc-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    4520a93c807cc135d0ca079a8d9d1127
java-1.5.0-sun-jdbc-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    4520a93c807cc135d0ca079a8d9d1127
java-1.5.0-sun-jdbc-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    4520a93c807cc135d0ca079a8d9d1127
java-1.5.0-sun-src-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    13e272c027e9c1773a549dd3641d5570
java-1.5.0-sun-src-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    13e272c027e9c1773a549dd3641d5570
java-1.5.0-sun-src-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    13e272c027e9c1773a549dd3641d5570
java-1.5.0-sun-src-1.5.0.14-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    13e272c027e9c1773a549dd3641d5570
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

431861 - CVE-2008-0657 java-1.5.0 Privilege escalation via unstrusted applet and application


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/