Security Advisory Critical: java-1.5.0-sun security update

Advisory: RHSA-2008:0186-3
Type: Security Advisory
Severity: Critical
Issued on: 2008-03-06
Last updated on: 2008-03-06
Affected Products: RHEL Desktop Supplementary (v. 5 client)
RHEL Supplementary (v. 5 server)
Red Hat Enterprise Linux Extras (v. 4)
OVAL: com.redhat.rhsa-20080186.xml
CVEs (cve.mitre.org): CVE-2008-1185
CVE-2008-1186
CVE-2008-1187
CVE-2008-1188
CVE-2008-1189
CVE-2008-1190
CVE-2008-1192
CVE-2008-1193
CVE-2008-1194
CVE-2008-1195
CVE-2008-1196

Details

Updated java-1.5.0-sun packages that correct several security issues are
now available for Red Hat Enterprise Linux 4 Extras and 5 Supplementary.

This update has been rated as having critical security impact by the Red
Hat Security Response Team.

The Java Runtime Environment (JRE) contains the software and tools
that users need to run applets and applications written using the Java
programming language.

Flaws in the JRE allowed an untrusted application or applet to elevate its
privileges. This could be exploited by a remote attacker to access local
files or execute local applications accessible to the user running the JRE
(CVE-2008-1185, CVE-2008-1186)

A flaw was found in the Java XSLT processing classes. An untrusted
application or applet could cause a denial of service, or execute arbitrary
code with the permissions of the user running the JRE. (CVE-2008-1187)

Several buffer overflow flaws were found in Java Web Start (JWS). An
untrusted JNLP application could access local files or execute local
applications accessible to the user running the JRE.
(CVE-2008-1188, CVE-2008-1189, CVE-2008-1190, CVE-2008-1191, CVE-2008-1196)

A flaw was found in the Java Plug-in. A remote attacker could bypass the
same origin policy, executing arbitrary code with the permissions of the
user running the JRE. (CVE-2008-1192)

A flaw was found in the JRE image parsing libraries. An untrusted
application or applet could cause a denial of service, or possible execute
arbitrary code with the permissions of the user running the JRE.
(CVE-2008-1193)

A flaw was found in the JRE color management library. An untrusted
application or applet could trigger a denial of service (JVM crash).
(CVE-2008-1194)

The JRE allowed untrusted JavaScript code to create local network
connections by the use of Java APIs. A remote attacker could use these
flaws to acesss local network services. (CVE-2008-1195)

This update also fixes an issue where the Java Plug-in is not available for
browser use after successful installation.

Users of java-1.5.0-sun should upgrade to these updated packages, which
correct these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

RHEL Desktop Supplementary (v. 5 client)

IA-32:
java-1.5.0-sun-1.5.0.15-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    18c3ac793bf0933535f34c4f34db10c6
java-1.5.0-sun-demo-1.5.0.15-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    1da388c51f565d0b597bea1c561c4df1
java-1.5.0-sun-devel-1.5.0.15-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    8d79e45143f711ac73c5c10eab72be04
java-1.5.0-sun-jdbc-1.5.0.15-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    5bc2343c3b36132f89226e813a85e14c
java-1.5.0-sun-plugin-1.5.0.15-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    8369328b32697f43b9a0031c19ce6491
java-1.5.0-sun-src-1.5.0.15-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    3058888e8ad21b71718731d5956f32ea
 
x86_64:
java-1.5.0-sun-1.5.0.15-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    0e0dfa1ddb4ffd4f363a8f5950dcedb7
java-1.5.0-sun-demo-1.5.0.15-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    d6fa0238a3d9ace335a1f0adf8a28390
java-1.5.0-sun-devel-1.5.0.15-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    75fb9b5e270557895665f41c291d1b22
java-1.5.0-sun-jdbc-1.5.0.15-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    e3645754fbd5ab444cea8e90ca8f90d8
java-1.5.0-sun-plugin-1.5.0.15-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    8369328b32697f43b9a0031c19ce6491
java-1.5.0-sun-src-1.5.0.15-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    0140541307f63daaa6463a6819574a00
 
RHEL Supplementary (v. 5 server)

IA-32:
java-1.5.0-sun-1.5.0.15-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    18c3ac793bf0933535f34c4f34db10c6
java-1.5.0-sun-demo-1.5.0.15-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    1da388c51f565d0b597bea1c561c4df1
java-1.5.0-sun-devel-1.5.0.15-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    8d79e45143f711ac73c5c10eab72be04
java-1.5.0-sun-jdbc-1.5.0.15-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    5bc2343c3b36132f89226e813a85e14c
java-1.5.0-sun-plugin-1.5.0.15-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    8369328b32697f43b9a0031c19ce6491
java-1.5.0-sun-src-1.5.0.15-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    3058888e8ad21b71718731d5956f32ea
 
x86_64:
java-1.5.0-sun-1.5.0.15-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    0e0dfa1ddb4ffd4f363a8f5950dcedb7
java-1.5.0-sun-demo-1.5.0.15-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    d6fa0238a3d9ace335a1f0adf8a28390
java-1.5.0-sun-devel-1.5.0.15-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    75fb9b5e270557895665f41c291d1b22
java-1.5.0-sun-jdbc-1.5.0.15-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    e3645754fbd5ab444cea8e90ca8f90d8
java-1.5.0-sun-plugin-1.5.0.15-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2008:0595
    8369328b32697f43b9a0031c19ce6491
java-1.5.0-sun-src-1.5.0.15-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2008:0595
    0140541307f63daaa6463a6819574a00
 
Red Hat Enterprise Linux Extras (v. 4)

IA-32:
java-1.5.0-sun-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    f900264d9f548756a3a41779540f7dd5
java-1.5.0-sun-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    f900264d9f548756a3a41779540f7dd5
java-1.5.0-sun-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    f900264d9f548756a3a41779540f7dd5
java-1.5.0-sun-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    f900264d9f548756a3a41779540f7dd5
java-1.5.0-sun-demo-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    7456312e87bffc0f31c00cf8744c58c6
java-1.5.0-sun-demo-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    7456312e87bffc0f31c00cf8744c58c6
java-1.5.0-sun-demo-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    7456312e87bffc0f31c00cf8744c58c6
java-1.5.0-sun-demo-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    7456312e87bffc0f31c00cf8744c58c6
java-1.5.0-sun-devel-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    f6dde9b5500012d45a7d09d6bd1c91f8
java-1.5.0-sun-devel-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    f6dde9b5500012d45a7d09d6bd1c91f8
java-1.5.0-sun-devel-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    f6dde9b5500012d45a7d09d6bd1c91f8
java-1.5.0-sun-devel-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    f6dde9b5500012d45a7d09d6bd1c91f8
java-1.5.0-sun-jdbc-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    914b36bcb1b38a2a35c7214fb85db79c
java-1.5.0-sun-jdbc-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    914b36bcb1b38a2a35c7214fb85db79c
java-1.5.0-sun-jdbc-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    914b36bcb1b38a2a35c7214fb85db79c
java-1.5.0-sun-jdbc-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    914b36bcb1b38a2a35c7214fb85db79c
java-1.5.0-sun-plugin-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    345d5b3a35839b6be94484f5a4d49eba
java-1.5.0-sun-plugin-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    345d5b3a35839b6be94484f5a4d49eba
java-1.5.0-sun-plugin-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    345d5b3a35839b6be94484f5a4d49eba
java-1.5.0-sun-plugin-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    345d5b3a35839b6be94484f5a4d49eba
java-1.5.0-sun-src-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    63c8d86432933c1bc16878c98528ab3a
java-1.5.0-sun-src-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    63c8d86432933c1bc16878c98528ab3a
java-1.5.0-sun-src-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    63c8d86432933c1bc16878c98528ab3a
java-1.5.0-sun-src-1.5.0.15-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2008:0595
    63c8d86432933c1bc16878c98528ab3a
 
x86_64:
java-1.5.0-sun-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    0cc2d6ee9020211167b7a8e03f81cb0d
java-1.5.0-sun-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    0cc2d6ee9020211167b7a8e03f81cb0d
java-1.5.0-sun-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    0cc2d6ee9020211167b7a8e03f81cb0d
java-1.5.0-sun-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    0cc2d6ee9020211167b7a8e03f81cb0d
java-1.5.0-sun-demo-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    63ce98ee7ac175d8cb9ef29f5d9d4932
java-1.5.0-sun-demo-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    63ce98ee7ac175d8cb9ef29f5d9d4932
java-1.5.0-sun-demo-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    63ce98ee7ac175d8cb9ef29f5d9d4932
java-1.5.0-sun-demo-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    63ce98ee7ac175d8cb9ef29f5d9d4932
java-1.5.0-sun-devel-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    067b97ab85d612af25894178319a97ae
java-1.5.0-sun-devel-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    067b97ab85d612af25894178319a97ae
java-1.5.0-sun-devel-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    067b97ab85d612af25894178319a97ae
java-1.5.0-sun-devel-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    067b97ab85d612af25894178319a97ae
java-1.5.0-sun-jdbc-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    ead105806d87079837dd1f6eab7a7d1e
java-1.5.0-sun-jdbc-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    ead105806d87079837dd1f6eab7a7d1e
java-1.5.0-sun-jdbc-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    ead105806d87079837dd1f6eab7a7d1e
java-1.5.0-sun-jdbc-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    ead105806d87079837dd1f6eab7a7d1e
java-1.5.0-sun-src-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    122eb81deb1930d53a46de94e23e9ff3
java-1.5.0-sun-src-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    122eb81deb1930d53a46de94e23e9ff3
java-1.5.0-sun-src-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    122eb81deb1930d53a46de94e23e9ff3
java-1.5.0-sun-src-1.5.0.15-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2008:0595
    122eb81deb1930d53a46de94e23e9ff3
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

436029 - CVE-2008-1185 Untrusted applet and application privilege escalation (CVE-2008-1186)
436030 - CVE-2008-1187 Untrusted applet and application XSLT processing privilege escalation
436293 - CVE-2008-1188 Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190, CVE-2008-1191)
436295 - CVE-2008-1192 Java Plugin same-origin-policy bypass
436296 - CVE-2008-1193 JRE image parsing library allows privilege escalation (CVE-2008-1194)
436299 - CVE-2008-1195 Java-API calls in untrusted Javascript allow network privilege escalation
436302 - CVE-2008-1196 Buffer overflow security vulnerabilities in Java Web Start


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/