Security Advisory Critical: java-1.5.0-sun security update

Advisory: RHSA-2008:1025-4
Type: Security Advisory
Severity: Critical
Issued on: 2008-12-04
Last updated on: 2008-12-04
Affected Products: RHEL Desktop Supplementary (v. 5 client)
RHEL Supplementary (v. 5 server)
RHEL Supplementary EUS (v. 5.2.z server)
Red Hat Enterprise Linux Extras (v. 4)
Red Hat Enterprise Linux Extras (v. 4.7.z)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2008-2086
CVE-2008-5339
CVE-2008-5340
CVE-2008-5341
CVE-2008-5342
CVE-2008-5343
CVE-2008-5344
CVE-2008-5345
CVE-2008-5346
CVE-2008-5348
CVE-2008-5349
CVE-2008-5350
CVE-2008-5351
CVE-2008-5352
CVE-2008-5353
CVE-2008-5354
CVE-2008-5356
CVE-2008-5357
CVE-2008-5359
CVE-2008-5360

Details

Updated java-1.5.0-sun packages that correct several security issues are
now available for Red Hat Enterprise Linux 4 Extras and 5 Supplementary.

This update has been rated as having critical security impact by the Red
Hat Security Response Team.

The Java Runtime Environment (JRE) contains the software and tools that
users need to run applets and applications written using the Java
programming language.

A vulnerability was found in in Java Web Start. If a user visits a
malicious website, an attacker could misuse this flaw to execute arbitrary
code. (CVE-2008-2086)

Additionally, these packages fix several other vulnerabilities. These are
summarized in the "Advance notification of Security Updates for Java SE"
from Sun Microsystems.

Users of java-1.5.0-sun should upgrade to these updated packages, which
correct these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

RHEL Desktop Supplementary (v. 5 client)

IA-32:
java-1.5.0-sun-1.5.0.17-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2009:1571
    62c3f51450df56e15da4820d31f811b4
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2009:1571
    8d59f9f96e1ab9e9c52cb2deb9637c55
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2009:1571
    4e11abeb5eda54c146ca26c380cf5239
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2009:1571
    c2dc2f38695bd4df288ebf16710d8c5c
java-1.5.0-sun-plugin-1.5.0.17-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2009:1571
    c56d77bd7fbd4454dd8f212e1bbea11b
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2009:1571
    d7f7bce39bf3e48027ce8d3465311f9e
 
x86_64:
java-1.5.0-sun-1.5.0.17-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2009:1571
    500a781f4c72560d421838c37ded6f76
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2009:1571
    dbe0f00c5dfdcebad266c676cb003a37
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2009:1571
    c4545d92c940aeb754996ed0b430cfab
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2009:1571
    d6d261b01e8496533970c3cf2c0fd9ec
java-1.5.0-sun-plugin-1.5.0.17-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2009:1571
    c56d77bd7fbd4454dd8f212e1bbea11b
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2009:1571
    9854b87958473de1693e4aed1f817440
 
RHEL Supplementary (v. 5 server)

IA-32:
java-1.5.0-sun-1.5.0.17-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2009:1571
    62c3f51450df56e15da4820d31f811b4
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2009:1571
    8d59f9f96e1ab9e9c52cb2deb9637c55
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2009:1571
    4e11abeb5eda54c146ca26c380cf5239
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2009:1571
    c2dc2f38695bd4df288ebf16710d8c5c
java-1.5.0-sun-plugin-1.5.0.17-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2009:1571
    c56d77bd7fbd4454dd8f212e1bbea11b
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2009:1571
    d7f7bce39bf3e48027ce8d3465311f9e
 
x86_64:
java-1.5.0-sun-1.5.0.17-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2009:1571
    500a781f4c72560d421838c37ded6f76
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2009:1571
    dbe0f00c5dfdcebad266c676cb003a37
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2009:1571
    c4545d92c940aeb754996ed0b430cfab
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2009:1571
    d6d261b01e8496533970c3cf2c0fd9ec
java-1.5.0-sun-plugin-1.5.0.17-1jpp.2.el5.i586.rpm
File outdated by:  RHSA-2009:1571
    c56d77bd7fbd4454dd8f212e1bbea11b
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el5.x86_64.rpm
File outdated by:  RHSA-2009:1571
    9854b87958473de1693e4aed1f817440
 
RHEL Supplementary EUS (v. 5.2.z server)

IA-32:
java-1.5.0-sun-1.5.0.17-1jpp.2.el5.i586.rpm     62c3f51450df56e15da4820d31f811b4
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el5.i586.rpm     8d59f9f96e1ab9e9c52cb2deb9637c55
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el5.i586.rpm     4e11abeb5eda54c146ca26c380cf5239
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el5.i586.rpm     c2dc2f38695bd4df288ebf16710d8c5c
java-1.5.0-sun-plugin-1.5.0.17-1jpp.2.el5.i586.rpm     c56d77bd7fbd4454dd8f212e1bbea11b
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el5.i586.rpm     d7f7bce39bf3e48027ce8d3465311f9e
 
x86_64:
java-1.5.0-sun-1.5.0.17-1jpp.2.el5.x86_64.rpm     500a781f4c72560d421838c37ded6f76
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el5.x86_64.rpm     dbe0f00c5dfdcebad266c676cb003a37
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el5.x86_64.rpm     c4545d92c940aeb754996ed0b430cfab
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el5.x86_64.rpm     d6d261b01e8496533970c3cf2c0fd9ec
java-1.5.0-sun-plugin-1.5.0.17-1jpp.2.el5.i586.rpm     c56d77bd7fbd4454dd8f212e1bbea11b
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el5.x86_64.rpm     9854b87958473de1693e4aed1f817440
 
Red Hat Enterprise Linux Extras (v. 4)

IA-32:
java-1.5.0-sun-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    0b077fd06b1f1a7b307a1839d221ed11
java-1.5.0-sun-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    0b077fd06b1f1a7b307a1839d221ed11
java-1.5.0-sun-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    0b077fd06b1f1a7b307a1839d221ed11
java-1.5.0-sun-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    0b077fd06b1f1a7b307a1839d221ed11
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    bcb0cb6a80637e82ab185d599d0f07fe
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    bcb0cb6a80637e82ab185d599d0f07fe
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    bcb0cb6a80637e82ab185d599d0f07fe
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    bcb0cb6a80637e82ab185d599d0f07fe
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    c5fb0cff9dc1d3739fe9334a4185718c
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    c5fb0cff9dc1d3739fe9334a4185718c
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    c5fb0cff9dc1d3739fe9334a4185718c
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    c5fb0cff9dc1d3739fe9334a4185718c
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    b34dfd27f0f290f096695ba70ff7566c
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    b34dfd27f0f290f096695ba70ff7566c
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    b34dfd27f0f290f096695ba70ff7566c
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    b34dfd27f0f290f096695ba70ff7566c
java-1.5.0-sun-plugin-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    b7dac8eef714df06fcdd9c4debf0a0a0
java-1.5.0-sun-plugin-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    b7dac8eef714df06fcdd9c4debf0a0a0
java-1.5.0-sun-plugin-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    b7dac8eef714df06fcdd9c4debf0a0a0
java-1.5.0-sun-plugin-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    b7dac8eef714df06fcdd9c4debf0a0a0
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    27c33de289659f415161c058fa3422bf
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    27c33de289659f415161c058fa3422bf
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    27c33de289659f415161c058fa3422bf
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:1571
    27c33de289659f415161c058fa3422bf
 
x86_64:
java-1.5.0-sun-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    eea820a934f0026e573f3f35d99d141c
java-1.5.0-sun-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    eea820a934f0026e573f3f35d99d141c
java-1.5.0-sun-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    eea820a934f0026e573f3f35d99d141c
java-1.5.0-sun-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    eea820a934f0026e573f3f35d99d141c
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    39b3a23c719ea68dd4625b01dc13ab00
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    39b3a23c719ea68dd4625b01dc13ab00
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    39b3a23c719ea68dd4625b01dc13ab00
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    39b3a23c719ea68dd4625b01dc13ab00
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    b77ce23525881c6782fcf3ffb3e26337
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    b77ce23525881c6782fcf3ffb3e26337
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    b77ce23525881c6782fcf3ffb3e26337
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    b77ce23525881c6782fcf3ffb3e26337
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    8f467388c5db2e703cdb30938dc10c4a
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    8f467388c5db2e703cdb30938dc10c4a
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    8f467388c5db2e703cdb30938dc10c4a
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    8f467388c5db2e703cdb30938dc10c4a
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    607dfff8695d09af74325707ba44ca48
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    607dfff8695d09af74325707ba44ca48
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    607dfff8695d09af74325707ba44ca48
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:1571
    607dfff8695d09af74325707ba44ca48
 
Red Hat Enterprise Linux Extras (v. 4.7.z)

IA-32:
java-1.5.0-sun-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:0394
    0b077fd06b1f1a7b307a1839d221ed11
java-1.5.0-sun-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:0394
    0b077fd06b1f1a7b307a1839d221ed11
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:0394
    bcb0cb6a80637e82ab185d599d0f07fe
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:0394
    bcb0cb6a80637e82ab185d599d0f07fe
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:0394
    c5fb0cff9dc1d3739fe9334a4185718c
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:0394
    c5fb0cff9dc1d3739fe9334a4185718c
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:0394
    b34dfd27f0f290f096695ba70ff7566c
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:0394
    b34dfd27f0f290f096695ba70ff7566c
java-1.5.0-sun-plugin-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:0394
    b7dac8eef714df06fcdd9c4debf0a0a0
java-1.5.0-sun-plugin-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:0394
    b7dac8eef714df06fcdd9c4debf0a0a0
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:0394
    27c33de289659f415161c058fa3422bf
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el4.i586.rpm
File outdated by:  RHSA-2009:0394
    27c33de289659f415161c058fa3422bf
 
x86_64:
java-1.5.0-sun-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:0394
    eea820a934f0026e573f3f35d99d141c
java-1.5.0-sun-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:0394
    eea820a934f0026e573f3f35d99d141c
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:0394
    39b3a23c719ea68dd4625b01dc13ab00
java-1.5.0-sun-demo-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:0394
    39b3a23c719ea68dd4625b01dc13ab00
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:0394
    b77ce23525881c6782fcf3ffb3e26337
java-1.5.0-sun-devel-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:0394
    b77ce23525881c6782fcf3ffb3e26337
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:0394
    8f467388c5db2e703cdb30938dc10c4a
java-1.5.0-sun-jdbc-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:0394
    8f467388c5db2e703cdb30938dc10c4a
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:0394
    607dfff8695d09af74325707ba44ca48
java-1.5.0-sun-src-1.5.0.17-1jpp.2.el4.x86_64.rpm
File outdated by:  RHSA-2009:0394
    607dfff8695d09af74325707ba44ca48
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

474556 - CVE-2008-2086 Java Web Start File Inclusion via System Properties Override


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/