Security Advisory Low: Red Hat Network Satellite Server IBM Java Runtime security update

Advisory: RHSA-2008:0638-4
Type: Security Advisory
Severity: Low
Issued on: 2008-08-13
Last updated on: 2008-08-13
Affected Products: Red Hat Network Satellite (v. 5.1 for RHEL 4)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2008-0657
CVE-2008-1187
CVE-2008-1188
CVE-2008-1189
CVE-2008-1190
CVE-2008-1192
CVE-2008-1193
CVE-2008-1194
CVE-2008-1195
CVE-2008-1196
CVE-2008-3104
CVE-2008-3106
CVE-2008-3108
CVE-2008-3111
CVE-2008-3112
CVE-2008-3113
CVE-2008-3114

Details

Red Hat Network Satellite Server version 5.1.1 is now available. This
update includes fixes for a number of security issues in the Red Hat
Network Satellite Server IBM Java Runtime Environment for IBM S/390 and IBM
System z architectures.

This update has been rated as having low security impact by the Red Hat
Security Response Team.

This release corrects several security vulnerabilities in the IBM Java
Runtime Environment shipped as part of Red Hat Network Satellite Server 5.1
for IBM S/390 and IBM System z architectures. In a typical operating
environment, these are of low security risk as the runtime is not used on
untrusted applets.

Multiple flaws were fixed in the IBM Java 1.5.0 Runtime Environment.
(CVE-2008-0657, CVE-2008-1187, CVE-2008-1188, CVE-2008-1189, CVE-2008-1190,
CVE-2008-1192, CVE-2008-1193, CVE-2008-1194, CVE-2008-1195, CVE-2008-1196,
CVE-2008-3104, CVE-2008-3106, CVE-2008-3108, CVE-2008-3111, CVE-2008-3112,
CVE-2008-3113, CVE-2008-3114)

Users of Red Hat Network Satellite Server 5.1 are advised to upgrade to
5.1.1, which resolves these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

Red Hat Network Satellite (v. 5.1 for RHEL 4)

s390:
java-1.5.0-ibm-1.5.0.8-1jpp.1.el4.s390.rpm     4225afb69c5a0e45fe4e0c3c56c4600b
java-1.5.0-ibm-devel-1.5.0.8-1jpp.1.el4.s390.rpm     f0e83f89327522c99c174e1d3603717a
 
s390x:
java-1.5.0-ibm-1.5.0.8-1jpp.1.el4.s390x.rpm     4e2e589e3b71b316539bb793461cddcb
java-1.5.0-ibm-devel-1.5.0.8-1jpp.1.el4.s390x.rpm     30aab8b015aa4f744b5b51808fcd612f
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

431861 - CVE-2008-0657 java-1.5.0 Privilege escalation via unstrusted applet and application
436030 - CVE-2008-1187 Untrusted applet and application XSLT processing privilege escalation
436293 - CVE-2008-1188 Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)
436295 - CVE-2008-1192 Java Plugin same-origin-policy bypass
436296 - CVE-2008-1193 JRE image parsing library allows privilege escalation (CVE-2008-1194)
436299 - CVE-2008-1195 Java-API calls in untrusted Javascript allow network privilege escalation
436302 - CVE-2008-1196 Buffer overflow security vulnerabilities in Java Web Start
452649 - CVE-2008-3105 CVE-2008-3106 OpenJDK JAX-WS unauthorized URL access (6542088)
454601 - CVE-2008-3104 Java RE allows Same Origin Policy to be Bypassed (6687932)
454604 - CVE-2008-3108 Security Vulnerability with JRE fonts processing may allow Elevation of Privileges (6450319)
454605 - CVE-2008-3111 Java Web Start Buffer overflow vulnerabilities (6557220)
454606 - CVE-2008-3112 Java Web Start, arbitrary file creation (6703909)
454607 - CVE-2008-3113 Java Web Start arbitrary file creation/deletion file with user permissions (6704077)
454608 - CVE-2008-3114 Java Web Start, untrusted application may determine Cache Location (6704074)


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/