Skip to navigation

Security Advisory Critical: java-1.6.0-openjdk security update

Advisory: RHSA-2013:0245-2
Type: Security Advisory
Severity: Critical
Issued on: 2013-02-08
Last updated on: 2013-02-08
Affected Products: Red Hat Enterprise Linux Desktop (v. 6)
Red Hat Enterprise Linux HPC Node (v. 6)
Red Hat Enterprise Linux Server (v. 6)
Red Hat Enterprise Linux Server EUS (v. 6.3.z)
Red Hat Enterprise Linux Workstation (v. 6)
CVEs (cve.mitre.org): CVE-2013-0424
CVE-2013-0425
CVE-2013-0426
CVE-2013-0427
CVE-2013-0428
CVE-2013-0429
CVE-2013-0432
CVE-2013-0433
CVE-2013-0434
CVE-2013-0435
CVE-2013-0440
CVE-2013-0441
CVE-2013-0442
CVE-2013-0443
CVE-2013-0445
CVE-2013-0450
CVE-2013-1475
CVE-2013-1476
CVE-2013-1478
CVE-2013-1480

Details

Updated java-1.6.0-openjdk packages that fix several security issues are
now available for Red Hat Enterprise Linux 6.

The Red Hat Security Response Team has rated this update as having critical
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.

These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

Multiple improper permission check issues were discovered in the AWT,
CORBA, JMX, and Libraries components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass Java sandbox
restrictions. (CVE-2013-0442, CVE-2013-0445, CVE-2013-0441, CVE-2013-1475,
CVE-2013-1476, CVE-2013-0429, CVE-2013-0450, CVE-2013-0425, CVE-2013-0426,
CVE-2013-0428)

Multiple flaws were found in the way image parsers in the 2D and AWT
components handled image raster parameters. A specially-crafted image could
cause Java Virtual Machine memory corruption and, possibly, lead to
arbitrary code execution with the virtual machine privileges.
(CVE-2013-1478, CVE-2013-1480)

A flaw was found in the AWT component's clipboard handling code. An
untrusted Java application or applet could use this flaw to access
clipboard data, bypassing Java sandbox restrictions. (CVE-2013-0432)

The default Java security properties configuration did not restrict access
to certain com.sun.xml.internal packages. An untrusted Java application or
applet could use this flaw to access information, bypassing certain Java
sandbox restrictions. This update lists the whole package as restricted.
(CVE-2013-0435)

Multiple improper permission check issues were discovered in the Libraries,
Networking, and JAXP components. An untrusted Java application or applet
could use these flaws to bypass certain Java sandbox restrictions.
(CVE-2013-0427, CVE-2013-0433, CVE-2013-0434)

It was discovered that the RMI component's CGIHandler class used user
inputs in error messages without any sanitization. An attacker could use
this flaw to perform a cross-site scripting (XSS) attack. (CVE-2013-0424)

It was discovered that the SSL/TLS implementation in the JSSE component
did not properly enforce handshake message ordering, allowing an unlimited
number of handshake restarts. A remote attacker could use this flaw to
make an SSL/TLS server using JSSE consume an excessive amount of CPU by
continuously restarting the handshake. (CVE-2013-0440)

It was discovered that the JSSE component did not properly validate
Diffie-Hellman public keys. An SSL/TLS client could possibly use this flaw
to perform a small subgroup attack. (CVE-2013-0443)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

This erratum also upgrades the OpenJDK package to IcedTea6 1.11.6. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.


Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258

Updated packages

Red Hat Enterprise Linux Desktop (v. 6)

SRPMS:
java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.src.rpm
File outdated by:  RHSA-2014:0408
    MD5: cb77de9111d005bf95c4914729f49982
SHA-256: eb3dce4f9dc4b1b8b1baf54dc9577414dd22b844a803cf00cffe0a9820443a99
 
IA-32:
java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: 2c3aa96b486bfb95aac87be344c330f0
SHA-256: b881fd05853528e2323cd7b5e5b0cbb6d2319a37a4c7ddf3aedea0a4babb1146
java-1.6.0-openjdk-debuginfo-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: be9302eb0da2a2687a66f918fc5c7ccd
SHA-256: 67ebd0619c44b914b8a1004be46b2a4ca5e33134b969edded90281f57822c64e
java-1.6.0-openjdk-demo-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: c64aa965c1cdda696d42bb0e59192ad5
SHA-256: 962691d195a570af28e5de9da9a987d07a4b827eb6e96ccf847a81abe563c5b5
java-1.6.0-openjdk-devel-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: caa12490c3cb5f97e641990651b502c0
SHA-256: 66a34cfd52c91efd1adc79089dfe8fa7d82f4dcd1ca1b302d22c25644bd4f48a
java-1.6.0-openjdk-javadoc-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: 21d807da1aff0decec17a25d29d147e2
SHA-256: da2555b3d995d110a2da0ec2190a90c35b97a8b46c6a2d63f8ddafe3b556b592
java-1.6.0-openjdk-src-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: 3e721c68bea2709bb3ab5a2b528141e0
SHA-256: 5c472f4d8bf2b72fbafd249fa2607a8ab9521aa4ac3783ae465277b92c82b021
 
x86_64:
java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: 9821fe8db0dbad202bc6fc2e8c98866b
SHA-256: 27b8febf1c62e788801811eb5a3b3f8a0759a6b2eed990416249beaec55929a3
java-1.6.0-openjdk-debuginfo-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: 65fe4fcec74b0b552e727b1b13726b10
SHA-256: 2aa0e745a9f138c5c1d3070b96c2b73be47704a7748f754f02948c8af03aa0d2
java-1.6.0-openjdk-demo-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: e7508bedd90244b479ab8236e98b97b6
SHA-256: 7fcaf3076932efa8fea7649346683596dc6c4e755636243f47eb0db7eb1c4d96
java-1.6.0-openjdk-devel-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: bce32bc9a2eb5cd0f82f44c72be8d370
SHA-256: 2b09e9afef34c4502e6f726b96ffeddc5fcdc7275de94c7f230c140cd5241346
java-1.6.0-openjdk-javadoc-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: 2372b8106801879dffff270174145f57
SHA-256: cee31972e3982fc479a7fd0fe272c174beb1e03fde7925f88fc514266a29a35a
java-1.6.0-openjdk-src-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: bc27360285748b804f945a1faa8cc545
SHA-256: 1688167dd2dde0a2e20b0df32a1706ed0d9300a90c7e3b9059c0f15929ff542a
 
Red Hat Enterprise Linux HPC Node (v. 6)

SRPMS:
java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.src.rpm
File outdated by:  RHSA-2014:0408
    MD5: cb77de9111d005bf95c4914729f49982
SHA-256: eb3dce4f9dc4b1b8b1baf54dc9577414dd22b844a803cf00cffe0a9820443a99
 
x86_64:
java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: 9821fe8db0dbad202bc6fc2e8c98866b
SHA-256: 27b8febf1c62e788801811eb5a3b3f8a0759a6b2eed990416249beaec55929a3
java-1.6.0-openjdk-debuginfo-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: 65fe4fcec74b0b552e727b1b13726b10
SHA-256: 2aa0e745a9f138c5c1d3070b96c2b73be47704a7748f754f02948c8af03aa0d2
java-1.6.0-openjdk-demo-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: e7508bedd90244b479ab8236e98b97b6
SHA-256: 7fcaf3076932efa8fea7649346683596dc6c4e755636243f47eb0db7eb1c4d96
java-1.6.0-openjdk-devel-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: bce32bc9a2eb5cd0f82f44c72be8d370
SHA-256: 2b09e9afef34c4502e6f726b96ffeddc5fcdc7275de94c7f230c140cd5241346
java-1.6.0-openjdk-javadoc-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: 2372b8106801879dffff270174145f57
SHA-256: cee31972e3982fc479a7fd0fe272c174beb1e03fde7925f88fc514266a29a35a
java-1.6.0-openjdk-src-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: bc27360285748b804f945a1faa8cc545
SHA-256: 1688167dd2dde0a2e20b0df32a1706ed0d9300a90c7e3b9059c0f15929ff542a
 
Red Hat Enterprise Linux Server (v. 6)

SRPMS:
java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.src.rpm
File outdated by:  RHSA-2014:0408
    MD5: cb77de9111d005bf95c4914729f49982
SHA-256: eb3dce4f9dc4b1b8b1baf54dc9577414dd22b844a803cf00cffe0a9820443a99
 
IA-32:
java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: 2c3aa96b486bfb95aac87be344c330f0
SHA-256: b881fd05853528e2323cd7b5e5b0cbb6d2319a37a4c7ddf3aedea0a4babb1146
java-1.6.0-openjdk-debuginfo-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: be9302eb0da2a2687a66f918fc5c7ccd
SHA-256: 67ebd0619c44b914b8a1004be46b2a4ca5e33134b969edded90281f57822c64e
java-1.6.0-openjdk-demo-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: c64aa965c1cdda696d42bb0e59192ad5
SHA-256: 962691d195a570af28e5de9da9a987d07a4b827eb6e96ccf847a81abe563c5b5
java-1.6.0-openjdk-devel-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: caa12490c3cb5f97e641990651b502c0
SHA-256: 66a34cfd52c91efd1adc79089dfe8fa7d82f4dcd1ca1b302d22c25644bd4f48a
java-1.6.0-openjdk-javadoc-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: 21d807da1aff0decec17a25d29d147e2
SHA-256: da2555b3d995d110a2da0ec2190a90c35b97a8b46c6a2d63f8ddafe3b556b592
java-1.6.0-openjdk-src-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: 3e721c68bea2709bb3ab5a2b528141e0
SHA-256: 5c472f4d8bf2b72fbafd249fa2607a8ab9521aa4ac3783ae465277b92c82b021
 
x86_64:
java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: 9821fe8db0dbad202bc6fc2e8c98866b
SHA-256: 27b8febf1c62e788801811eb5a3b3f8a0759a6b2eed990416249beaec55929a3
java-1.6.0-openjdk-debuginfo-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: 65fe4fcec74b0b552e727b1b13726b10
SHA-256: 2aa0e745a9f138c5c1d3070b96c2b73be47704a7748f754f02948c8af03aa0d2
java-1.6.0-openjdk-demo-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: e7508bedd90244b479ab8236e98b97b6
SHA-256: 7fcaf3076932efa8fea7649346683596dc6c4e755636243f47eb0db7eb1c4d96
java-1.6.0-openjdk-devel-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: bce32bc9a2eb5cd0f82f44c72be8d370
SHA-256: 2b09e9afef34c4502e6f726b96ffeddc5fcdc7275de94c7f230c140cd5241346
java-1.6.0-openjdk-javadoc-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: 2372b8106801879dffff270174145f57
SHA-256: cee31972e3982fc479a7fd0fe272c174beb1e03fde7925f88fc514266a29a35a
java-1.6.0-openjdk-src-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: bc27360285748b804f945a1faa8cc545
SHA-256: 1688167dd2dde0a2e20b0df32a1706ed0d9300a90c7e3b9059c0f15929ff542a
 
Red Hat Enterprise Linux Server EUS (v. 6.3.z)

SRPMS:
java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.src.rpm
File outdated by:  RHSA-2014:0408
    MD5: cb77de9111d005bf95c4914729f49982
SHA-256: eb3dce4f9dc4b1b8b1baf54dc9577414dd22b844a803cf00cffe0a9820443a99
 
IA-32:
java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2013:0273
    MD5: 2c3aa96b486bfb95aac87be344c330f0
SHA-256: b881fd05853528e2323cd7b5e5b0cbb6d2319a37a4c7ddf3aedea0a4babb1146
java-1.6.0-openjdk-debuginfo-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2013:0273
    MD5: be9302eb0da2a2687a66f918fc5c7ccd
SHA-256: 67ebd0619c44b914b8a1004be46b2a4ca5e33134b969edded90281f57822c64e
java-1.6.0-openjdk-demo-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2013:0273
    MD5: c64aa965c1cdda696d42bb0e59192ad5
SHA-256: 962691d195a570af28e5de9da9a987d07a4b827eb6e96ccf847a81abe563c5b5
java-1.6.0-openjdk-devel-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2013:0273
    MD5: caa12490c3cb5f97e641990651b502c0
SHA-256: 66a34cfd52c91efd1adc79089dfe8fa7d82f4dcd1ca1b302d22c25644bd4f48a
java-1.6.0-openjdk-javadoc-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2013:0273
    MD5: 21d807da1aff0decec17a25d29d147e2
SHA-256: da2555b3d995d110a2da0ec2190a90c35b97a8b46c6a2d63f8ddafe3b556b592
java-1.6.0-openjdk-src-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2013:0273
    MD5: 3e721c68bea2709bb3ab5a2b528141e0
SHA-256: 5c472f4d8bf2b72fbafd249fa2607a8ab9521aa4ac3783ae465277b92c82b021
 
x86_64:
java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2013:0273
    MD5: 9821fe8db0dbad202bc6fc2e8c98866b
SHA-256: 27b8febf1c62e788801811eb5a3b3f8a0759a6b2eed990416249beaec55929a3
java-1.6.0-openjdk-debuginfo-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2013:0273
    MD5: 65fe4fcec74b0b552e727b1b13726b10
SHA-256: 2aa0e745a9f138c5c1d3070b96c2b73be47704a7748f754f02948c8af03aa0d2
java-1.6.0-openjdk-demo-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2013:0273
    MD5: e7508bedd90244b479ab8236e98b97b6
SHA-256: 7fcaf3076932efa8fea7649346683596dc6c4e755636243f47eb0db7eb1c4d96
java-1.6.0-openjdk-devel-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2013:0273
    MD5: bce32bc9a2eb5cd0f82f44c72be8d370
SHA-256: 2b09e9afef34c4502e6f726b96ffeddc5fcdc7275de94c7f230c140cd5241346
java-1.6.0-openjdk-javadoc-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2013:0273
    MD5: 2372b8106801879dffff270174145f57
SHA-256: cee31972e3982fc479a7fd0fe272c174beb1e03fde7925f88fc514266a29a35a
java-1.6.0-openjdk-src-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2013:0273
    MD5: bc27360285748b804f945a1faa8cc545
SHA-256: 1688167dd2dde0a2e20b0df32a1706ed0d9300a90c7e3b9059c0f15929ff542a
 
Red Hat Enterprise Linux Workstation (v. 6)

SRPMS:
java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.src.rpm
File outdated by:  RHSA-2014:0408
    MD5: cb77de9111d005bf95c4914729f49982
SHA-256: eb3dce4f9dc4b1b8b1baf54dc9577414dd22b844a803cf00cffe0a9820443a99
 
IA-32:
java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: 2c3aa96b486bfb95aac87be344c330f0
SHA-256: b881fd05853528e2323cd7b5e5b0cbb6d2319a37a4c7ddf3aedea0a4babb1146
java-1.6.0-openjdk-debuginfo-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: be9302eb0da2a2687a66f918fc5c7ccd
SHA-256: 67ebd0619c44b914b8a1004be46b2a4ca5e33134b969edded90281f57822c64e
java-1.6.0-openjdk-demo-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: c64aa965c1cdda696d42bb0e59192ad5
SHA-256: 962691d195a570af28e5de9da9a987d07a4b827eb6e96ccf847a81abe563c5b5
java-1.6.0-openjdk-devel-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: caa12490c3cb5f97e641990651b502c0
SHA-256: 66a34cfd52c91efd1adc79089dfe8fa7d82f4dcd1ca1b302d22c25644bd4f48a
java-1.6.0-openjdk-javadoc-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: 21d807da1aff0decec17a25d29d147e2
SHA-256: da2555b3d995d110a2da0ec2190a90c35b97a8b46c6a2d63f8ddafe3b556b592
java-1.6.0-openjdk-src-1.6.0.0-1.54.1.11.6.el6_3.i686.rpm
File outdated by:  RHSA-2014:0408
    MD5: 3e721c68bea2709bb3ab5a2b528141e0
SHA-256: 5c472f4d8bf2b72fbafd249fa2607a8ab9521aa4ac3783ae465277b92c82b021
 
x86_64:
java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: 9821fe8db0dbad202bc6fc2e8c98866b
SHA-256: 27b8febf1c62e788801811eb5a3b3f8a0759a6b2eed990416249beaec55929a3
java-1.6.0-openjdk-debuginfo-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: 65fe4fcec74b0b552e727b1b13726b10
SHA-256: 2aa0e745a9f138c5c1d3070b96c2b73be47704a7748f754f02948c8af03aa0d2
java-1.6.0-openjdk-demo-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: e7508bedd90244b479ab8236e98b97b6
SHA-256: 7fcaf3076932efa8fea7649346683596dc6c4e755636243f47eb0db7eb1c4d96
java-1.6.0-openjdk-devel-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: bce32bc9a2eb5cd0f82f44c72be8d370
SHA-256: 2b09e9afef34c4502e6f726b96ffeddc5fcdc7275de94c7f230c140cd5241346
java-1.6.0-openjdk-javadoc-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: 2372b8106801879dffff270174145f57
SHA-256: cee31972e3982fc479a7fd0fe272c174beb1e03fde7925f88fc514266a29a35a
java-1.6.0-openjdk-src-1.6.0.0-1.54.1.11.6.el6_3.x86_64.rpm
File outdated by:  RHSA-2014:0408
    MD5: bc27360285748b804f945a1faa8cc545
SHA-256: 1688167dd2dde0a2e20b0df32a1706ed0d9300a90c7e3b9059c0f15929ff542a
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

859140 - CVE-2013-0440 OpenJDK: CPU consumption DoS via repeated SSL ClientHello packets (JSSE, 7192393)
860652 - CVE-2013-1475 OpenJDK: IIOP type reuse sandbox bypass (CORBA, 8000540, SE-2012-01 Issue 50)
906813 - CVE-2013-0424 OpenJDK: RMI CGIHandler XSS issue (RMI, 6563318)
906892 - CVE-2013-0435 OpenJDK: com.sun.xml.internal.* not restricted packages (JAX-WS, 7201068)
906894 - CVE-2013-1478 OpenJDK: image parser insufficient raster parameter checks (2D, 8001972)
906899 - CVE-2013-0442 OpenJDK: insufficient privilege checking issue (AWT, 7192977)
906900 - CVE-2013-0445 OpenJDK: insufficient privilege checking issue (AWT, 8001057)
906904 - CVE-2013-1480 OpenJDK: image parser insufficient raster parameter checks (AWT, 8002325)
906911 - CVE-2013-0450 OpenJDK: RequiredModelMBean missing access control context checks (JMX, 8000537)
907207 - CVE-2013-0428 OpenJDK: reflection API incorrect checks for proxy classes (Libraries, 7197546, SE-2012-01 Issue 29)
907219 - CVE-2013-0432 OpenJDK: insufficient clipboard access premission checks (AWT, 7186952)
907340 - CVE-2013-0443 OpenJDK: insufficient Diffie-Hellman public key checks (JSSE, 7192392)
907344 - CVE-2013-0425 OpenJDK: logging insufficient access control checks (Libraries, 6664509)
907346 - CVE-2013-0426 OpenJDK: logging insufficient access control checks (Libraries, 6664528)
907453 - CVE-2013-0434 OpenJDK: loadPropertyFile missing restrictions (JAXP, 8001235)
907455 - CVE-2013-0427 OpenJDK: invalid threads subject to interrupts (Libraries, 6776941)
907456 - CVE-2013-0433 OpenJDK: InetSocketAddress serialization issue (Networking, 7201071)
907457 - CVE-2013-1476 OpenJDK: missing ValueHandlerImpl class constructor access restriction (CORBA, 8000631)
907458 - CVE-2013-0441 OpenJDK: missing serialization restriction (CORBA, 7201066)
907460 - CVE-2013-0429 OpenJDK: PresentationManager incorrectly shared (CORBA, 7141694)


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/