Security Advisory Low: Red Hat Network Satellite Server Sun Java Runtime security update

Advisory: RHSA-2008:0636-4
Type: Security Advisory
Severity: Low
Issued on: 2008-08-13
Last updated on: 2008-08-13
Affected Products: Red Hat Network Satellite (v. 5.1 for RHEL 4)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2008-3103
CVE-2008-3104
CVE-2008-3107
CVE-2008-3111
CVE-2008-3112
CVE-2008-3113
CVE-2008-3114

Details

Red Hat Network Satellite Server version 5.1.1 is now available. This
update includes fixes for a number of security issues in the Red Hat
Network Satellite Server Sun Java Runtime Environment.

This update has been rated as having low security impact by the Red Hat
Security Response Team.

This release corrects several security vulnerabilities in the Sun Java
Runtime Environment shipped as part of Red Hat Network Satellite Server
5.1. In a typical operating environment, these are of low security risk as
the runtime is not used on untrusted applets.

Multiple flaws were fixed in the Sun Java 1.5.0 Runtime Environment.
(CVE-2008-3103, CVE-2008-3104, CVE-2008-3107, CVE-2008-3111, CVE-2008-3112,
CVE-2008-3113, CVE-2008-3114)

Users of Red Hat Network Satellite Server 5.1 are advised to upgrade to
5.1.1, which resolves these issues.


Solution

This update is available via Red Hat Network. Details on how to use the
Red Hat Network to apply this update are available at
http://www.redhat.com/docs/manuals/satellite/Red_Hat_Network_Satellite-5.1.0/html/Installation_Guide/s1-maintenance-update.html

Updated packages

Red Hat Network Satellite (v. 5.1 for RHEL 4)

IA-32:
java-1.5.0-sun-1.5.0.16-1jpp.2.el4.i586.rpm     c0829c731e49e9bb51e1b06f41c6d303
java-1.5.0-sun-devel-1.5.0.16-1jpp.2.el4.i586.rpm     6419c40658bd9adf7b9449a60d2a3f2b
 
x86_64:
java-1.5.0-sun-1.5.0.16-1jpp.2.el4.x86_64.rpm     e075f5c9b5440e251e5ff003d9fb8660
java-1.5.0-sun-devel-1.5.0.16-1jpp.2.el4.x86_64.rpm     dba09cc89b800d4e030544fb735cfde3
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

452658 - CVE-2008-3107 JDK untrusted applet/application privilege escalation (6661918)
452659 - CVE-2008-3103 OpenJDK JMX allows illegal operations with local monitoring (6332953)
454601 - CVE-2008-3104 Java RE allows Same Origin Policy to be Bypassed (6687932)
454605 - CVE-2008-3111 Java Web Start Buffer overflow vulnerabilities (6557220)
454606 - CVE-2008-3112 Java Web Start, arbitrary file creation (6703909)
454607 - CVE-2008-3113 Java Web Start arbitrary file creation/deletion file with user permissions (6704077)
454608 - CVE-2008-3114 Java Web Start, untrusted application may determine Cache Location (6704074)


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/