Skip to navigation

Security Advisory Critical: java-1.6.0-sun security update

Advisory: RHSA-2010:0770-1
Type: Security Advisory
Severity: Critical
Issued on: 2010-10-14
Last updated on: 2010-10-14
Affected Products: RHEL Desktop Supplementary (v. 5 client)
RHEL Supplementary (v. 5 server)
Red Hat Enterprise Linux Extras (v. 4)
Red Hat Enterprise Linux Extras (v. 4.8.z)
CVEs (cve.mitre.org): CVE-2009-3555
CVE-2010-1321
CVE-2010-3541
CVE-2010-3548
CVE-2010-3549
CVE-2010-3550
CVE-2010-3551
CVE-2010-3552
CVE-2010-3553
CVE-2010-3554
CVE-2010-3555
CVE-2010-3556
CVE-2010-3557
CVE-2010-3558
CVE-2010-3559
CVE-2010-3560
CVE-2010-3561
CVE-2010-3562
CVE-2010-3563
CVE-2010-3565
CVE-2010-3566
CVE-2010-3567
CVE-2010-3568
CVE-2010-3569
CVE-2010-3570
CVE-2010-3571
CVE-2010-3572
CVE-2010-3573
CVE-2010-3574

Details

Updated java-1.6.0-sun packages that fix several security issues are now
available for Red Hat Enterprise Linux 4 Extras and 5 Supplementary.

The Red Hat Security Response Team has rated this update as having critical
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.

The Sun 1.6.0 Java release includes the Sun Java 6 Runtime Environment and
the Sun Java 6 Software Development Kit.

This update fixes several vulnerabilities in the Sun Java 6 Runtime
Environment and the Sun Java 6 Software Development Kit. Further
information about these flaws can be found on the "Oracle Java SE and Java
for Business Critical Patch Update Advisory" page, listed in the References
section. (CVE-2010-1321, CVE-2010-3541, CVE-2010-3548, CVE-2010-3549,
CVE-2010-3550, CVE-2010-3551, CVE-2010-3552, CVE-2010-3553, CVE-2010-3554,
CVE-2010-3555, CVE-2010-3556, CVE-2010-3557, CVE-2010-3558, CVE-2010-3559,
CVE-2010-3560, CVE-2010-3561, CVE-2010-3562, CVE-2010-3563, CVE-2010-3565,
CVE-2010-3566, CVE-2010-3567, CVE-2010-3568, CVE-2010-3569, CVE-2010-3570,
CVE-2010-3571, CVE-2010-3572, CVE-2010-3573, CVE-2010-3574)

The RHSA-2010:0337 update mitigated a man-in-the-middle attack in the way
the TLS/SSL (Transport Layer Security/Secure Sockets Layer) protocols
handle session renegotiation by disabling renegotiation. This update
implements the TLS Renegotiation Indication Extension as defined in RFC
5746, allowing secure renegotiation between updated clients and servers.
(CVE-2009-3555)

Users of java-1.6.0-sun should upgrade to these updated packages, which
correct these issues. All running instances of Sun Java must be restarted
for the update to take effect.


Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

RHEL Desktop Supplementary (v. 5 client)

IA-32:
java-1.6.0-sun-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 117b699deac08071a8e2a2aa060e9d33
SHA-256: 1f73fcf3b28a2740d4025e2d643cefe792132e754fed915f17a14dc8171aa932
java-1.6.0-sun-demo-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 847a818f5f357959bada031dfa9fddc0
SHA-256: 4d24c79da1a3f0126cf62f91ab53b2620aa4c393f3f9a44b7e95cafb64268757
java-1.6.0-sun-devel-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: fd2685d9b1a59320f1d8ff8434ab45c5
SHA-256: dd09a6788315716d53f0ff2d0d3906e8438d515c9c31b94da5a4147762b40a26
java-1.6.0-sun-jdbc-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 39e49ed945dd292c85dc820e731d8760
SHA-256: 948d6248414c032363bdb6eb26c3c952b479907584912dbe5e338922c004b5da
java-1.6.0-sun-plugin-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: b4fe1d22c7c2f88e46f78ab6203a290d
SHA-256: 3ed077373ed77334aac7667306e16a87686393a25c791d68e4d6e5eba7c4c841
java-1.6.0-sun-src-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 4e822f28914a5e9526db66c63eef5f88
SHA-256: 7408213936c8b1be2b03c3c196f32aa39d1e8be63ee31fc7865901b4b064a69c
 
x86_64:
java-1.6.0-sun-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 117b699deac08071a8e2a2aa060e9d33
SHA-256: 1f73fcf3b28a2740d4025e2d643cefe792132e754fed915f17a14dc8171aa932
java-1.6.0-sun-1.6.0.22-1jpp.1.el5.x86_64.rpm     MD5: 81f79a71e42f9bc6608d8d7eda8cc29a
SHA-256: 95c49e0689d7f113d3569e75ace1aed9dcb9631d9212a0d07f196f2113ff72b2
java-1.6.0-sun-demo-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 847a818f5f357959bada031dfa9fddc0
SHA-256: 4d24c79da1a3f0126cf62f91ab53b2620aa4c393f3f9a44b7e95cafb64268757
java-1.6.0-sun-demo-1.6.0.22-1jpp.1.el5.x86_64.rpm     MD5: 5b64f23f3eba9b4f39b236a38d0c8579
SHA-256: 9f91bda7d150e40019742196e5f9d077fa1e1bf6d0411416f2225d2d8966cb6e
java-1.6.0-sun-devel-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: fd2685d9b1a59320f1d8ff8434ab45c5
SHA-256: dd09a6788315716d53f0ff2d0d3906e8438d515c9c31b94da5a4147762b40a26
java-1.6.0-sun-devel-1.6.0.22-1jpp.1.el5.x86_64.rpm     MD5: e0883f15935704176c8296a1f7f22cf3
SHA-256: 1874946e66cb58e0cdf2b1ad31c0defdb85da37b774f1da28950f85a510c74eb
java-1.6.0-sun-jdbc-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 39e49ed945dd292c85dc820e731d8760
SHA-256: 948d6248414c032363bdb6eb26c3c952b479907584912dbe5e338922c004b5da
java-1.6.0-sun-jdbc-1.6.0.22-1jpp.1.el5.x86_64.rpm     MD5: f77ca36c6f32bae5f045aa221f82d099
SHA-256: 5c382de56b09e7115f39179dfa7099b0f3b7a2853b85b6a6fc7c99d9673c6945
java-1.6.0-sun-plugin-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: b4fe1d22c7c2f88e46f78ab6203a290d
SHA-256: 3ed077373ed77334aac7667306e16a87686393a25c791d68e4d6e5eba7c4c841
java-1.6.0-sun-plugin-1.6.0.22-1jpp.1.el5.x86_64.rpm     MD5: 09fa11deb8ed8f6a9cd67fb72e726318
SHA-256: 4f0692d97a4b5a476b7e15cba964882c559ffce24ce98ff3ffb4c2445e64529d
java-1.6.0-sun-src-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 4e822f28914a5e9526db66c63eef5f88
SHA-256: 7408213936c8b1be2b03c3c196f32aa39d1e8be63ee31fc7865901b4b064a69c
java-1.6.0-sun-src-1.6.0.22-1jpp.1.el5.x86_64.rpm     MD5: 40ad819297eed6581394eddcdae6d229
SHA-256: d6c9916f1b3b91a25060507b6443e826592adf46b81435c938bf309169c33fe1
 
RHEL Supplementary (v. 5 server)

IA-32:
java-1.6.0-sun-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 117b699deac08071a8e2a2aa060e9d33
SHA-256: 1f73fcf3b28a2740d4025e2d643cefe792132e754fed915f17a14dc8171aa932
java-1.6.0-sun-demo-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 847a818f5f357959bada031dfa9fddc0
SHA-256: 4d24c79da1a3f0126cf62f91ab53b2620aa4c393f3f9a44b7e95cafb64268757
java-1.6.0-sun-devel-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: fd2685d9b1a59320f1d8ff8434ab45c5
SHA-256: dd09a6788315716d53f0ff2d0d3906e8438d515c9c31b94da5a4147762b40a26
java-1.6.0-sun-jdbc-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 39e49ed945dd292c85dc820e731d8760
SHA-256: 948d6248414c032363bdb6eb26c3c952b479907584912dbe5e338922c004b5da
java-1.6.0-sun-plugin-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: b4fe1d22c7c2f88e46f78ab6203a290d
SHA-256: 3ed077373ed77334aac7667306e16a87686393a25c791d68e4d6e5eba7c4c841
java-1.6.0-sun-src-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 4e822f28914a5e9526db66c63eef5f88
SHA-256: 7408213936c8b1be2b03c3c196f32aa39d1e8be63ee31fc7865901b4b064a69c
 
x86_64:
java-1.6.0-sun-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 117b699deac08071a8e2a2aa060e9d33
SHA-256: 1f73fcf3b28a2740d4025e2d643cefe792132e754fed915f17a14dc8171aa932
java-1.6.0-sun-1.6.0.22-1jpp.1.el5.x86_64.rpm     MD5: 81f79a71e42f9bc6608d8d7eda8cc29a
SHA-256: 95c49e0689d7f113d3569e75ace1aed9dcb9631d9212a0d07f196f2113ff72b2
java-1.6.0-sun-demo-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 847a818f5f357959bada031dfa9fddc0
SHA-256: 4d24c79da1a3f0126cf62f91ab53b2620aa4c393f3f9a44b7e95cafb64268757
java-1.6.0-sun-demo-1.6.0.22-1jpp.1.el5.x86_64.rpm     MD5: 5b64f23f3eba9b4f39b236a38d0c8579
SHA-256: 9f91bda7d150e40019742196e5f9d077fa1e1bf6d0411416f2225d2d8966cb6e
java-1.6.0-sun-devel-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: fd2685d9b1a59320f1d8ff8434ab45c5
SHA-256: dd09a6788315716d53f0ff2d0d3906e8438d515c9c31b94da5a4147762b40a26
java-1.6.0-sun-devel-1.6.0.22-1jpp.1.el5.x86_64.rpm     MD5: e0883f15935704176c8296a1f7f22cf3
SHA-256: 1874946e66cb58e0cdf2b1ad31c0defdb85da37b774f1da28950f85a510c74eb
java-1.6.0-sun-jdbc-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 39e49ed945dd292c85dc820e731d8760
SHA-256: 948d6248414c032363bdb6eb26c3c952b479907584912dbe5e338922c004b5da
java-1.6.0-sun-jdbc-1.6.0.22-1jpp.1.el5.x86_64.rpm     MD5: f77ca36c6f32bae5f045aa221f82d099
SHA-256: 5c382de56b09e7115f39179dfa7099b0f3b7a2853b85b6a6fc7c99d9673c6945
java-1.6.0-sun-plugin-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: b4fe1d22c7c2f88e46f78ab6203a290d
SHA-256: 3ed077373ed77334aac7667306e16a87686393a25c791d68e4d6e5eba7c4c841
java-1.6.0-sun-plugin-1.6.0.22-1jpp.1.el5.x86_64.rpm     MD5: 09fa11deb8ed8f6a9cd67fb72e726318
SHA-256: 4f0692d97a4b5a476b7e15cba964882c559ffce24ce98ff3ffb4c2445e64529d
java-1.6.0-sun-src-1.6.0.22-1jpp.1.el5.i586.rpm     MD5: 4e822f28914a5e9526db66c63eef5f88
SHA-256: 7408213936c8b1be2b03c3c196f32aa39d1e8be63ee31fc7865901b4b064a69c
java-1.6.0-sun-src-1.6.0.22-1jpp.1.el5.x86_64.rpm     MD5: 40ad819297eed6581394eddcdae6d229
SHA-256: d6c9916f1b3b91a25060507b6443e826592adf46b81435c938bf309169c33fe1
 
Red Hat Enterprise Linux Extras (v. 4)

IA-32:
java-1.6.0-sun-1.6.0.22-1jpp.1.el4.i586.rpm
File outdated by:  RHSA-2012:0139
    MD5: 6c2f360d5b9298e2538d5b6201e74560
SHA-256: 7b72a5fda594badd069a74b966e066c90100c48b62a137b08b839a02fda1b22e
java-1.6.0-sun-demo-1.6.0.22-1jpp.1.el4.i586.rpm
File outdated by:  RHSA-2012:0139
    MD5: ce9b8642ce81696171a4e3bc1c9814a6
SHA-256: 0731e0d27fd79fc02d6ff14a3fbf6c5f956970a027ba548f4ca0d2920adeb702
java-1.6.0-sun-devel-1.6.0.22-1jpp.1.el4.i586.rpm
File outdated by:  RHSA-2012:0139
    MD5: a455817c6737904440fc070c44da31c0
SHA-256: 71ce68d252fa26e69c7d193c911f4667d72e172a039e8017e7088d2b1bacb8e3
java-1.6.0-sun-jdbc-1.6.0.22-1jpp.1.el4.i586.rpm
File outdated by:  RHSA-2012:0139
    MD5: fef8159071e69b7cb899a59ee366ccdd
SHA-256: 11277ac68ab087df97c5cbb6fb430d81a4e0cb772d4be44f6a12e787c2a1435e
java-1.6.0-sun-plugin-1.6.0.22-1jpp.1.el4.i586.rpm
File outdated by:  RHSA-2012:0139
    MD5: a262694be645188f597da8f4fcf47504
SHA-256: 611fb72b1c5915a3ce0b2765a7189333828a504f129d5198c78263c459bbba2e
java-1.6.0-sun-src-1.6.0.22-1jpp.1.el4.i586.rpm
File outdated by:  RHSA-2012:0139
    MD5: 17a2899d999ffa6becde7121b42cef41
SHA-256: bf36438c953834a6600e90f910930a49f45ec801e5ee32b81ad690e2dd8d6e67
 
x86_64:
java-1.6.0-sun-1.6.0.22-1jpp.1.el4.x86_64.rpm
File outdated by:  RHSA-2012:0139
    MD5: 8174bb14da793d92de3c1dca8a61525d
SHA-256: 0ff6f5d7736f693b176db2e89a83f2c5a1e6432d60c8da2d1571b10881d224e7
java-1.6.0-sun-demo-1.6.0.22-1jpp.1.el4.x86_64.rpm
File outdated by:  RHSA-2012:0139
    MD5: 7f8d4466c78effefa903b1a489000607
SHA-256: 6000343527e1c6d2816ad8dced34669ea7a58003e2fad31438c8da1692cc2849
java-1.6.0-sun-devel-1.6.0.22-1jpp.1.el4.x86_64.rpm
File outdated by:  RHSA-2012:0139
    MD5: ca1c39f00a4d422da09f8a292eef4397
SHA-256: a9e9417d25c5a97ac83d9e37b6dccf42991cd86b5423f9b759cdb0b7ae02cf82
java-1.6.0-sun-jdbc-1.6.0.22-1jpp.1.el4.x86_64.rpm
File outdated by:  RHSA-2012:0139
    MD5: 9bb1c9fbdc66ee9866ccdb3922a2696f
SHA-256: 0722ca164dc01b45d8b2c63d1f489db9044e94f2631c00cbd05a0f4923439203
java-1.6.0-sun-plugin-1.6.0.22-1jpp.1.el4.x86_64.rpm
File outdated by:  RHSA-2012:0139
    MD5: ee10f970a6154d1c922c56d16ad59264
SHA-256: 1669b98e6139ebdcde7a918b9bd0212415c6b63f88d1c7aebef6ead3559c1e2b
java-1.6.0-sun-src-1.6.0.22-1jpp.1.el4.x86_64.rpm
File outdated by:  RHSA-2012:0139
    MD5: 72266ceca731addcd57e6b67eb892a39
SHA-256: 480ae336ef61826d3eb7455c3b0bc9b7c92b8c554934e71717bbf4a90cd853df
 
Red Hat Enterprise Linux Extras (v. 4.8.z)

IA-32:
java-1.6.0-sun-1.6.0.22-1jpp.1.el4.i586.rpm
File outdated by:  RHBA-2011:0835
    MD5: 6c2f360d5b9298e2538d5b6201e74560
SHA-256: 7b72a5fda594badd069a74b966e066c90100c48b62a137b08b839a02fda1b22e
java-1.6.0-sun-demo-1.6.0.22-1jpp.1.el4.i586.rpm
File outdated by:  RHBA-2011:0835
    MD5: ce9b8642ce81696171a4e3bc1c9814a6
SHA-256: 0731e0d27fd79fc02d6ff14a3fbf6c5f956970a027ba548f4ca0d2920adeb702
java-1.6.0-sun-devel-1.6.0.22-1jpp.1.el4.i586.rpm
File outdated by:  RHBA-2011:0835
    MD5: a455817c6737904440fc070c44da31c0
SHA-256: 71ce68d252fa26e69c7d193c911f4667d72e172a039e8017e7088d2b1bacb8e3
java-1.6.0-sun-jdbc-1.6.0.22-1jpp.1.el4.i586.rpm
File outdated by:  RHBA-2011:0835
    MD5: fef8159071e69b7cb899a59ee366ccdd
SHA-256: 11277ac68ab087df97c5cbb6fb430d81a4e0cb772d4be44f6a12e787c2a1435e
java-1.6.0-sun-plugin-1.6.0.22-1jpp.1.el4.i586.rpm
File outdated by:  RHBA-2011:0835
    MD5: a262694be645188f597da8f4fcf47504
SHA-256: 611fb72b1c5915a3ce0b2765a7189333828a504f129d5198c78263c459bbba2e
java-1.6.0-sun-src-1.6.0.22-1jpp.1.el4.i586.rpm
File outdated by:  RHBA-2011:0835
    MD5: 17a2899d999ffa6becde7121b42cef41
SHA-256: bf36438c953834a6600e90f910930a49f45ec801e5ee32b81ad690e2dd8d6e67
 
x86_64:
java-1.6.0-sun-1.6.0.22-1jpp.1.el4.x86_64.rpm
File outdated by:  RHBA-2011:0835
    MD5: 8174bb14da793d92de3c1dca8a61525d
SHA-256: 0ff6f5d7736f693b176db2e89a83f2c5a1e6432d60c8da2d1571b10881d224e7
java-1.6.0-sun-demo-1.6.0.22-1jpp.1.el4.x86_64.rpm
File outdated by:  RHBA-2011:0835
    MD5: 7f8d4466c78effefa903b1a489000607
SHA-256: 6000343527e1c6d2816ad8dced34669ea7a58003e2fad31438c8da1692cc2849
java-1.6.0-sun-devel-1.6.0.22-1jpp.1.el4.x86_64.rpm
File outdated by:  RHBA-2011:0835
    MD5: ca1c39f00a4d422da09f8a292eef4397
SHA-256: a9e9417d25c5a97ac83d9e37b6dccf42991cd86b5423f9b759cdb0b7ae02cf82
java-1.6.0-sun-jdbc-1.6.0.22-1jpp.1.el4.x86_64.rpm
File outdated by:  RHBA-2011:0835
    MD5: 9bb1c9fbdc66ee9866ccdb3922a2696f
SHA-256: 0722ca164dc01b45d8b2c63d1f489db9044e94f2631c00cbd05a0f4923439203
java-1.6.0-sun-plugin-1.6.0.22-1jpp.1.el4.x86_64.rpm
File outdated by:  RHBA-2011:0835
    MD5: ee10f970a6154d1c922c56d16ad59264
SHA-256: 1669b98e6139ebdcde7a918b9bd0212415c6b63f88d1c7aebef6ead3559c1e2b
java-1.6.0-sun-src-1.6.0.22-1jpp.1.el4.x86_64.rpm
File outdated by:  RHBA-2011:0835
    MD5: 72266ceca731addcd57e6b67eb892a39
SHA-256: 480ae336ef61826d3eb7455c3b0bc9b7c92b8c554934e71717bbf4a90cd853df
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

533125 - CVE-2009-3555 TLS: MITM attacks via session renegotiation
582466 - CVE-2010-1321 krb5: null pointer dereference in GSS-API library leads to DoS (MITKRB5-SA-2010-005)
639876 - CVE-2010-3568 OpenJDK Deserialization Race condition (6559775)
639880 - CVE-2010-3554 CVE-2010-3561 OpenJDK corba reflection vulnerabilities (6891766,6925672)
639897 - CVE-2010-3562 OpenJDK IndexColorModel double-free (6925710)
639904 - CVE-2010-3557 OpenJDK Swing mutable static (6938813)
639909 - CVE-2010-3548 OpenJDK DNS server IP address information leak (6957564)
639920 - CVE-2010-3565 OpenJDK JPEG writeImage remote code execution (6963023)
639922 - CVE-2010-3566 OpenJDK ICC Profile remote code execution (6963489)
639925 - CVE-2010-3569 OpenJDK Serialization inconsistencies (6966692)
642167 - CVE-2010-3553 OpenJDK Swing unsafe reflection usage (6622002)
642180 - CVE-2010-3549 OpenJDK HttpURLConnection request splitting (6952017)
642187 - CVE-2010-3551 OpenJDK local network address disclosure (6952603)
642197 - CVE-2010-3567 OpenJDK ICU Opentype layout engine crash (6963285)
642202 - CVE-2010-3541 CVE-2010-3573 OpenJDK HttpURLConnection allows arbitrary request headers (6961084,6980004)
642215 - CVE-2010-3574 OpenJDK HttpURLConnection incomplete TRACE permission check (6981426)
642558 - CVE-2010-3555 JDK unspecified vulnerability in Deployment component
642559 - CVE-2010-3550 JDK unspecified vulnerability in Java Web Start component
642561 - CVE-2010-3570 JDK unspecified vulnerability in Deployment Toolkit
642573 - CVE-2010-3560 JDK unspecified vulnerability in Networking component
642576 - CVE-2010-3556 JDK unspecified vulnerability in 2D component
642585 - CVE-2010-3571 JDK unspecified vulnerability in 2D component
642589 - CVE-2010-3563 JDK unspecified vulnerability in Deployment component
642593 - CVE-2010-3558 JDK unspecified vulnerability in Java Web Start component
642600 - CVE-2010-3552 JDK unspecified vulnerability in New Java Plugin component
642606 - CVE-2010-3559 JDK unspecified vulnerability in Sound component
642611 - CVE-2010-3572 JDK unspecified vulnerability in Sound component


References

https://www.redhat.com/security/data/cve/CVE-2009-3555.html
https://www.redhat.com/security/data/cve/CVE-2010-1321.html
https://www.redhat.com/security/data/cve/CVE-2010-3541.html
https://www.redhat.com/security/data/cve/CVE-2010-3548.html
https://www.redhat.com/security/data/cve/CVE-2010-3549.html
https://www.redhat.com/security/data/cve/CVE-2010-3550.html
https://www.redhat.com/security/data/cve/CVE-2010-3551.html
https://www.redhat.com/security/data/cve/CVE-2010-3552.html
https://www.redhat.com/security/data/cve/CVE-2010-3553.html
https://www.redhat.com/security/data/cve/CVE-2010-3554.html
https://www.redhat.com/security/data/cve/CVE-2010-3555.html
https://www.redhat.com/security/data/cve/CVE-2010-3556.html
https://www.redhat.com/security/data/cve/CVE-2010-3557.html
https://www.redhat.com/security/data/cve/CVE-2010-3558.html
https://www.redhat.com/security/data/cve/CVE-2010-3559.html
https://www.redhat.com/security/data/cve/CVE-2010-3560.html
https://www.redhat.com/security/data/cve/CVE-2010-3561.html
https://www.redhat.com/security/data/cve/CVE-2010-3562.html
https://www.redhat.com/security/data/cve/CVE-2010-3563.html
https://www.redhat.com/security/data/cve/CVE-2010-3565.html
https://www.redhat.com/security/data/cve/CVE-2010-3566.html
https://www.redhat.com/security/data/cve/CVE-2010-3567.html
https://www.redhat.com/security/data/cve/CVE-2010-3568.html
https://www.redhat.com/security/data/cve/CVE-2010-3569.html
https://www.redhat.com/security/data/cve/CVE-2010-3570.html
https://www.redhat.com/security/data/cve/CVE-2010-3571.html
https://www.redhat.com/security/data/cve/CVE-2010-3572.html
https://www.redhat.com/security/data/cve/CVE-2010-3573.html
https://www.redhat.com/security/data/cve/CVE-2010-3574.html
http://www.redhat.com/security/updates/classification/#critical
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
https://access.redhat.com/kb/docs/DOC-20491


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/