Security Advisory Critical: java-1.5.0-sun security update

Advisory: RHSA-2009:1571-1
Type: Security Advisory
Severity: Critical
Issued on: 2009-11-10
Last updated on: 2009-11-10
Affected Products: RHEL Desktop Supplementary (v. 5 client)
RHEL Supplementary (v. 5 server)
RHEL Supplementary EUS (v. 5.4.z server)
Red Hat Enterprise Linux Extras (v. 4)
Red Hat Enterprise Linux Extras (v. 4.8.z)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2009-2409
CVE-2009-3728
CVE-2009-3873
CVE-2009-3876
CVE-2009-3877
CVE-2009-3879
CVE-2009-3880
CVE-2009-3881
CVE-2009-3882
CVE-2009-3883
CVE-2009-3884

Details

Updated java-1.5.0-sun packages that correct several security issues are
now available for Red Hat Enterprise Linux 4 Extras and 5 Supplementary.

This update has been rated as having critical security impact by the Red
Hat Security Response Team.

The Sun 1.5.0 Java release includes the Sun Java 5 Runtime Environment and
the Sun Java 5 Software Development Kit.

This update fixes several vulnerabilities in the Sun Java 5 Runtime
Environment and the Sun Java 5 Software Development Kit. These
vulnerabilities are summarized on the "Advance notification of Security
Updates for Java SE" page from Sun Microsystems, listed in the References
section. (CVE-2009-2409, CVE-2009-3728, CVE-2009-3873, CVE-2009-3876,
CVE-2009-3877, CVE-2009-3879, CVE-2009-3880, CVE-2009-3881, CVE-2009-3882,
CVE-2009-3883, CVE-2009-3884)

Note: This is the final update for the java-1.5.0-sun packages, as the Sun
Java SE Release family 5.0 has now reached End of Service Life. The next
update will remove the java-1.5.0-sun packages.

An alternative to Sun Java SE 5.0 is the Java 2 Technology Edition of the
IBM Developer Kit for Linux, which is available from the Extras and
Supplementary channels on the Red Hat Network. For users of applications
that are capable of using the Java 6 runtime, the OpenJDK open source JDK
is included in Red Hat Enterprise Linux 5 (since 5.3) and is supported by
Red Hat.

Users of java-1.5.0-sun should upgrade to these updated packages, which
correct these issues. All running instances of Sun Java must be restarted
for the update to take effect.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

RHEL Desktop Supplementary (v. 5 client)

IA-32:
java-1.5.0-sun-1.5.0.22-1jpp.1.el5.i586.rpm     8ed6bcbc28ec897329a84455f738b759
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el5.i586.rpm     de67f19f6280f2b4721bbc5a08b48616
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el5.i586.rpm     fa10a3594b4a5c59af5fe5d19c424ead
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el5.i586.rpm     68381393a336c30b95d89a465cdda33d
java-1.5.0-sun-plugin-1.5.0.22-1jpp.1.el5.i586.rpm     1f976b26868c503214cef6a342463914
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el5.i586.rpm     913320ef9f9fa4ee0312cef9dc517c67
 
x86_64:
java-1.5.0-sun-1.5.0.22-1jpp.1.el5.x86_64.rpm     d8957c369389ab8f5417687c382eaa3a
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el5.x86_64.rpm     9b8d337819a2300be172d282796f9b4f
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el5.x86_64.rpm     948bd6cec0332521083e43376df58837
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el5.x86_64.rpm     e72fa20aab78270bc5df83a236acb7c0
java-1.5.0-sun-plugin-1.5.0.22-1jpp.1.el5.i586.rpm     1f976b26868c503214cef6a342463914
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el5.x86_64.rpm     256974fcf7525c3b8956b16b6f3a167f
 
RHEL Supplementary (v. 5 server)

IA-32:
java-1.5.0-sun-1.5.0.22-1jpp.1.el5.i586.rpm     8ed6bcbc28ec897329a84455f738b759
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el5.i586.rpm     de67f19f6280f2b4721bbc5a08b48616
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el5.i586.rpm     fa10a3594b4a5c59af5fe5d19c424ead
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el5.i586.rpm     68381393a336c30b95d89a465cdda33d
java-1.5.0-sun-plugin-1.5.0.22-1jpp.1.el5.i586.rpm     1f976b26868c503214cef6a342463914
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el5.i586.rpm     913320ef9f9fa4ee0312cef9dc517c67
 
x86_64:
java-1.5.0-sun-1.5.0.22-1jpp.1.el5.x86_64.rpm     d8957c369389ab8f5417687c382eaa3a
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el5.x86_64.rpm     9b8d337819a2300be172d282796f9b4f
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el5.x86_64.rpm     948bd6cec0332521083e43376df58837
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el5.x86_64.rpm     e72fa20aab78270bc5df83a236acb7c0
java-1.5.0-sun-plugin-1.5.0.22-1jpp.1.el5.i586.rpm     1f976b26868c503214cef6a342463914
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el5.x86_64.rpm     256974fcf7525c3b8956b16b6f3a167f
 
RHEL Supplementary EUS (v. 5.4.z server)

IA-32:
java-1.5.0-sun-1.5.0.22-1jpp.1.el5.i586.rpm     8ed6bcbc28ec897329a84455f738b759
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el5.i586.rpm     de67f19f6280f2b4721bbc5a08b48616
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el5.i586.rpm     fa10a3594b4a5c59af5fe5d19c424ead
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el5.i586.rpm     68381393a336c30b95d89a465cdda33d
java-1.5.0-sun-plugin-1.5.0.22-1jpp.1.el5.i586.rpm     1f976b26868c503214cef6a342463914
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el5.i586.rpm     913320ef9f9fa4ee0312cef9dc517c67
 
x86_64:
java-1.5.0-sun-1.5.0.22-1jpp.1.el5.x86_64.rpm     d8957c369389ab8f5417687c382eaa3a
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el5.x86_64.rpm     9b8d337819a2300be172d282796f9b4f
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el5.x86_64.rpm     948bd6cec0332521083e43376df58837
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el5.x86_64.rpm     e72fa20aab78270bc5df83a236acb7c0
java-1.5.0-sun-plugin-1.5.0.22-1jpp.1.el5.i586.rpm     1f976b26868c503214cef6a342463914
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el5.x86_64.rpm     256974fcf7525c3b8956b16b6f3a167f
 
Red Hat Enterprise Linux Extras (v. 4)

IA-32:
java-1.5.0-sun-1.5.0.22-1jpp.1.el4.i586.rpm     49cb8084d26b2f3c17d55f3dbf4865fc
java-1.5.0-sun-1.5.0.22-1jpp.1.el4.i586.rpm     49cb8084d26b2f3c17d55f3dbf4865fc
java-1.5.0-sun-1.5.0.22-1jpp.1.el4.i586.rpm     49cb8084d26b2f3c17d55f3dbf4865fc
java-1.5.0-sun-1.5.0.22-1jpp.1.el4.i586.rpm     49cb8084d26b2f3c17d55f3dbf4865fc
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el4.i586.rpm     4b46014c0adc27de5fd7e771aeb92e78
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el4.i586.rpm     4b46014c0adc27de5fd7e771aeb92e78
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el4.i586.rpm     4b46014c0adc27de5fd7e771aeb92e78
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el4.i586.rpm     4b46014c0adc27de5fd7e771aeb92e78
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el4.i586.rpm     09074b954b797a9f0b067a35e4d5f3e7
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el4.i586.rpm     09074b954b797a9f0b067a35e4d5f3e7
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el4.i586.rpm     09074b954b797a9f0b067a35e4d5f3e7
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el4.i586.rpm     09074b954b797a9f0b067a35e4d5f3e7
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el4.i586.rpm     8057aa05bb923589cfdad819f557aa8c
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el4.i586.rpm     8057aa05bb923589cfdad819f557aa8c
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el4.i586.rpm     8057aa05bb923589cfdad819f557aa8c
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el4.i586.rpm     8057aa05bb923589cfdad819f557aa8c
java-1.5.0-sun-plugin-1.5.0.22-1jpp.1.el4.i586.rpm     a333a20008196a5497b3be9ae1ff694b
java-1.5.0-sun-plugin-1.5.0.22-1jpp.1.el4.i586.rpm     a333a20008196a5497b3be9ae1ff694b
java-1.5.0-sun-plugin-1.5.0.22-1jpp.1.el4.i586.rpm     a333a20008196a5497b3be9ae1ff694b
java-1.5.0-sun-plugin-1.5.0.22-1jpp.1.el4.i586.rpm     a333a20008196a5497b3be9ae1ff694b
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el4.i586.rpm     ed1ce6fa5546e4d12401980094c85d63
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el4.i586.rpm     ed1ce6fa5546e4d12401980094c85d63
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el4.i586.rpm     ed1ce6fa5546e4d12401980094c85d63
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el4.i586.rpm     ed1ce6fa5546e4d12401980094c85d63
 
x86_64:
java-1.5.0-sun-1.5.0.22-1jpp.1.el4.x86_64.rpm     1cead532cd4929c7f047448e308a5d81
java-1.5.0-sun-1.5.0.22-1jpp.1.el4.x86_64.rpm     1cead532cd4929c7f047448e308a5d81
java-1.5.0-sun-1.5.0.22-1jpp.1.el4.x86_64.rpm     1cead532cd4929c7f047448e308a5d81
java-1.5.0-sun-1.5.0.22-1jpp.1.el4.x86_64.rpm     1cead532cd4929c7f047448e308a5d81
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el4.x86_64.rpm     45885ad412684bd1a07a75fcabb58765
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el4.x86_64.rpm     45885ad412684bd1a07a75fcabb58765
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el4.x86_64.rpm     45885ad412684bd1a07a75fcabb58765
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el4.x86_64.rpm     45885ad412684bd1a07a75fcabb58765
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el4.x86_64.rpm     bdb65e5bd38098f5fc4bb99fe0f3770c
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el4.x86_64.rpm     bdb65e5bd38098f5fc4bb99fe0f3770c
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el4.x86_64.rpm     bdb65e5bd38098f5fc4bb99fe0f3770c
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el4.x86_64.rpm     bdb65e5bd38098f5fc4bb99fe0f3770c
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el4.x86_64.rpm     5e57d3960c65537214727edd40e2e315
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el4.x86_64.rpm     5e57d3960c65537214727edd40e2e315
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el4.x86_64.rpm     5e57d3960c65537214727edd40e2e315
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el4.x86_64.rpm     5e57d3960c65537214727edd40e2e315
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el4.x86_64.rpm     733358906efae220d4ac52b83c4e388f
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el4.x86_64.rpm     733358906efae220d4ac52b83c4e388f
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el4.x86_64.rpm     733358906efae220d4ac52b83c4e388f
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el4.x86_64.rpm     733358906efae220d4ac52b83c4e388f
 
Red Hat Enterprise Linux Extras (v. 4.8.z)

IA-32:
java-1.5.0-sun-1.5.0.22-1jpp.1.el4.i586.rpm     49cb8084d26b2f3c17d55f3dbf4865fc
java-1.5.0-sun-1.5.0.22-1jpp.1.el4.i586.rpm     49cb8084d26b2f3c17d55f3dbf4865fc
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el4.i586.rpm     4b46014c0adc27de5fd7e771aeb92e78
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el4.i586.rpm     4b46014c0adc27de5fd7e771aeb92e78
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el4.i586.rpm     09074b954b797a9f0b067a35e4d5f3e7
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el4.i586.rpm     09074b954b797a9f0b067a35e4d5f3e7
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el4.i586.rpm     8057aa05bb923589cfdad819f557aa8c
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el4.i586.rpm     8057aa05bb923589cfdad819f557aa8c
java-1.5.0-sun-plugin-1.5.0.22-1jpp.1.el4.i586.rpm     a333a20008196a5497b3be9ae1ff694b
java-1.5.0-sun-plugin-1.5.0.22-1jpp.1.el4.i586.rpm     a333a20008196a5497b3be9ae1ff694b
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el4.i586.rpm     ed1ce6fa5546e4d12401980094c85d63
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el4.i586.rpm     ed1ce6fa5546e4d12401980094c85d63
 
x86_64:
java-1.5.0-sun-1.5.0.22-1jpp.1.el4.x86_64.rpm     1cead532cd4929c7f047448e308a5d81
java-1.5.0-sun-1.5.0.22-1jpp.1.el4.x86_64.rpm     1cead532cd4929c7f047448e308a5d81
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el4.x86_64.rpm     45885ad412684bd1a07a75fcabb58765
java-1.5.0-sun-demo-1.5.0.22-1jpp.1.el4.x86_64.rpm     45885ad412684bd1a07a75fcabb58765
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el4.x86_64.rpm     bdb65e5bd38098f5fc4bb99fe0f3770c
java-1.5.0-sun-devel-1.5.0.22-1jpp.1.el4.x86_64.rpm     bdb65e5bd38098f5fc4bb99fe0f3770c
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el4.x86_64.rpm     5e57d3960c65537214727edd40e2e315
java-1.5.0-sun-jdbc-1.5.0.22-1jpp.1.el4.x86_64.rpm     5e57d3960c65537214727edd40e2e315
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el4.x86_64.rpm     733358906efae220d4ac52b83c4e388f
java-1.5.0-sun-src-1.5.0.22-1jpp.1.el4.x86_64.rpm     733358906efae220d4ac52b83c4e388f
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

510197 - CVE-2009-2409 deprecate MD2 in SSL cert validation (Kaminsky)
530053 - CVE-2009-3873 OpenJDK JPEG Image Writer quantization problem (6862968)
530061 - CVE-2009-3876 OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877
530098 - CVE-2009-3728 OpenJDK ICC_Profile file existence detection information leak (6631533)
530173 - CVE-2009-3881 OpenJDK resurrected classloaders can still have children (6636650)
530175 - CVE-2009-3882 CVE-2009-3883 OpenJDK information leaks in mutable variables (6657026,6657138)
530296 - CVE-2009-3880 OpenJDK UI logging information leakage(6664512)
530297 - CVE-2009-3879 OpenJDK GraphicsConfiguration information leak(6822057)
530300 - CVE-2009-3884 OpenJDK zoneinfo file existence information leak (6824265)


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/