Security Advisory Important: java-1.6.0-sun security update

Advisory: RHSA-2014:0414-2
Type: Security Advisory
Severity: Important
Issued on: 2014-04-17
Last updated on: 2014-05-12
Affected Products: Oracle Java for RHEL (v. 5 server)
Oracle Java for RHEL Desktop (v. 5 client)
Oracle Java for Red Hat Enterprise Linux Desktop (v. 6)
Oracle Java for Red Hat Enterprise Linux HPC Node (v. 6)
Oracle Java for Red Hat Enterprise Linux Server (v. 6)
Oracle Java for Red Hat Enterprise Linux Server AUS (v. 6.5)
Oracle Java for Red Hat Enterprise Linux Server EUS (v. 6.5.z)
Oracle Java for Red Hat Enterprise Linux Workstation (v. 6)
CVEs (cve.mitre.org): CVE-2013-1500
CVE-2013-1571
CVE-2013-2407
CVE-2013-2412
CVE-2013-2437
CVE-2013-2442
CVE-2013-2443
CVE-2013-2444
CVE-2013-2445
CVE-2013-2446
CVE-2013-2447
CVE-2013-2448
CVE-2013-2450
CVE-2013-2451
CVE-2013-2452
CVE-2013-2453
CVE-2013-2454
CVE-2013-2455
CVE-2013-2456
CVE-2013-2457
CVE-2013-2459
CVE-2013-2461
CVE-2013-2463
CVE-2013-2464
CVE-2013-2465
CVE-2013-2466
CVE-2013-2468
CVE-2013-2469
CVE-2013-2470
CVE-2013-2471
CVE-2013-2472
CVE-2013-2473
CVE-2013-3743
CVE-2013-3829
CVE-2013-4002
CVE-2013-5772
CVE-2013-5774
CVE-2013-5776
CVE-2013-5778
CVE-2013-5780
CVE-2013-5782
CVE-2013-5783
CVE-2013-5784
CVE-2013-5787
CVE-2013-5789
CVE-2013-5790
CVE-2013-5797
CVE-2013-5801
CVE-2013-5802
CVE-2013-5803
CVE-2013-5804
CVE-2013-5809
CVE-2013-5812
CVE-2013-5814
CVE-2013-5817
CVE-2013-5818
CVE-2013-5819
CVE-2013-5820
CVE-2013-5823
CVE-2013-5824
CVE-2013-5825
CVE-2013-5829
CVE-2013-5830
CVE-2013-5831
CVE-2013-5832
CVE-2013-5840
CVE-2013-5842
CVE-2013-5843
CVE-2013-5848
CVE-2013-5849
CVE-2013-5850
CVE-2013-5852
CVE-2013-5878
CVE-2013-5884
CVE-2013-5887
CVE-2013-5888
CVE-2013-5889
CVE-2013-5896
CVE-2013-5898
CVE-2013-5899
CVE-2013-5902
CVE-2013-5905
CVE-2013-5906
CVE-2013-5907
CVE-2013-5910
CVE-2013-6629
CVE-2013-6954
CVE-2014-0368
CVE-2014-0373
CVE-2014-0375
CVE-2014-0376
CVE-2014-0387
CVE-2014-0403
CVE-2014-0410
CVE-2014-0411
CVE-2014-0415
CVE-2014-0416
CVE-2014-0417
CVE-2014-0418
CVE-2014-0422
CVE-2014-0423
CVE-2014-0424
CVE-2014-0428
CVE-2014-0429
CVE-2014-0446
CVE-2014-0449
CVE-2014-0451
CVE-2014-0452
CVE-2014-0453
CVE-2014-0456
CVE-2014-0457
CVE-2014-0458
CVE-2014-0460
CVE-2014-0461
CVE-2014-1876
CVE-2014-2398
CVE-2014-2401
CVE-2014-2403
CVE-2014-2409
CVE-2014-2412
CVE-2014-2414
CVE-2014-2420
CVE-2014-2421
CVE-2014-2423
CVE-2014-2427
CVE-2014-2428

Details

Updated java-1.6.0-sun packages that fix several security issues are now
available for Oracle Java for Red Hat Enterprise Linux 5 and 6.

The Red Hat Security Response Team has rated this update as having
Important security impact. Common Vulnerability Scoring System (CVSS) base
scores, which give detailed severity ratings, are available for each
vulnerability from the CVE links in the References section.

[Updated 12th May 2014]
The package list in this erratum has been updated to make the packages
available in the Oracle Java for Red Hat Enterprise Linux 6 Workstation
x86_64 channels on the Red Hat Network.

Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory pages, listed in the References section.
(CVE-2013-1500, CVE-2013-1571, CVE-2013-2407, CVE-2013-2412, CVE-2013-2437,
CVE-2013-2442, CVE-2013-2443, CVE-2013-2444, CVE-2013-2445, CVE-2013-2446,
CVE-2013-2447, CVE-2013-2448, CVE-2013-2450, CVE-2013-2451, CVE-2013-2452,
CVE-2013-2453, CVE-2013-2454, CVE-2013-2455, CVE-2013-2456, CVE-2013-2457,
CVE-2013-2459, CVE-2013-2461, CVE-2013-2463, CVE-2013-2464, CVE-2013-2465,
CVE-2013-2466, CVE-2013-2468, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471,
CVE-2013-2472, CVE-2013-2473, CVE-2013-3743, CVE-2013-3829, CVE-2013-4002,
CVE-2013-5772, CVE-2013-5774, CVE-2013-5776, CVE-2013-5778, CVE-2013-5780,
CVE-2013-5782, CVE-2013-5783, CVE-2013-5784, CVE-2013-5787, CVE-2013-5789,
CVE-2013-5790, CVE-2013-5797, CVE-2013-5801, CVE-2013-5802, CVE-2013-5803,
CVE-2013-5804, CVE-2013-5809, CVE-2013-5812, CVE-2013-5814, CVE-2013-5817,
CVE-2013-5818, CVE-2013-5819, CVE-2013-5820, CVE-2013-5823, CVE-2013-5824,
CVE-2013-5825, CVE-2013-5829, CVE-2013-5830, CVE-2013-5831, CVE-2013-5832,
CVE-2013-5840, CVE-2013-5842, CVE-2013-5843, CVE-2013-5848, CVE-2013-5849,
CVE-2013-5850, CVE-2013-5852, CVE-2013-5878, CVE-2013-5884, CVE-2013-5887,
CVE-2013-5888, CVE-2013-5889, CVE-2013-5896, CVE-2013-5898, CVE-2013-5899,
CVE-2013-5902, CVE-2013-5905, CVE-2013-5906, CVE-2013-5907, CVE-2013-5910,
CVE-2013-6629, CVE-2013-6954, CVE-2014-0368, CVE-2014-0373, CVE-2014-0375,
CVE-2014-0376, CVE-2014-0387, CVE-2014-0403, CVE-2014-0410, CVE-2014-0411,
CVE-2014-0415, CVE-2014-0416, CVE-2014-0417, CVE-2014-0418, CVE-2014-0422,
CVE-2014-0423, CVE-2014-0424, CVE-2014-0428, CVE-2014-0429, CVE-2014-0446,
CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453, CVE-2014-0456,
CVE-2014-0457, CVE-2014-0458, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2403, CVE-2014-2409, CVE-2014-2412,
CVE-2014-2414, CVE-2014-2420, CVE-2014-2421, CVE-2014-2423, CVE-2014-2427,
CVE-2014-2428)

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 75 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/site/articles/11258

Updated packages

Oracle Java for RHEL (v. 5 server)

IA-32:
java-1.6.0-sun-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: cf976db889b1344ea652173f075b228f
SHA-256: 31f5a47d78ca71e9bab6c8c49cf2e5a97a5c90ba53fea06e16dd45b69f403273
java-1.6.0-sun-demo-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: 7c0553a103cf4c6499f739d0599395b9
SHA-256: ea2308b884f187d8ca933bee51f138a32a226bd7b57161641f16d3dae9f29c00
java-1.6.0-sun-devel-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: 57ce767c5f8ef1259e954a2a66cd628b
SHA-256: a6c36982b938047ffe277fe5c092754fe9be65fdf64c35e37d864a68448a8758
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: e4c041c6d3d1b071434b4f286c9edf92
SHA-256: a4a3234d882671b4082fb494f34d6c80086635304b74992a23fd5ece7960b3d0
java-1.6.0-sun-plugin-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: c88e399a73b30e96172b43df3eef171b
SHA-256: aae82f962f097b141de308ca11032f3ee1fa34657691cb28dcb0dae7775554aa
java-1.6.0-sun-src-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: 1ce8c407b4762d6a36b79b6f53500f48
SHA-256: fb06abede2559681e946611f19f3212d8865011fcd3579643baa591d49350b98
 
x86_64:
java-1.6.0-sun-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: cf976db889b1344ea652173f075b228f
SHA-256: 31f5a47d78ca71e9bab6c8c49cf2e5a97a5c90ba53fea06e16dd45b69f403273
java-1.6.0-sun-1.6.0.75-1jpp.3.el5_10.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 87ff30ab10114ea706dfb4428948e4fe
SHA-256: 40b5d9bb265c5cdd16b080516d7b6eec9f6477f6c74dd16032a1253c694658d5
java-1.6.0-sun-demo-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: 7c0553a103cf4c6499f739d0599395b9
SHA-256: ea2308b884f187d8ca933bee51f138a32a226bd7b57161641f16d3dae9f29c00
java-1.6.0-sun-demo-1.6.0.75-1jpp.3.el5_10.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 0c2bf48a75976bcc99be725aed95247f
SHA-256: d89e95633f5471c7d99b81b459bbb8ff59e0cc091574e9e88703007d090ba20e
java-1.6.0-sun-devel-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: 57ce767c5f8ef1259e954a2a66cd628b
SHA-256: a6c36982b938047ffe277fe5c092754fe9be65fdf64c35e37d864a68448a8758
java-1.6.0-sun-devel-1.6.0.75-1jpp.3.el5_10.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 732259beddf2d51d0f7f713093695b11
SHA-256: 1614fd8eafd6b1cca5f6d9a22b12ac6a68a6f8f9e0624898ff9ca56425e77dd5
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: e4c041c6d3d1b071434b4f286c9edf92
SHA-256: a4a3234d882671b4082fb494f34d6c80086635304b74992a23fd5ece7960b3d0
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.3.el5_10.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: f4e0877aab74f8050f3d08dfc27ee6c4
SHA-256: 83647228f8a4fa8c0ec9f0d24cd5b85b0ea3619b09ceef22e22fdfb61644fb9b
java-1.6.0-sun-plugin-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: c88e399a73b30e96172b43df3eef171b
SHA-256: aae82f962f097b141de308ca11032f3ee1fa34657691cb28dcb0dae7775554aa
java-1.6.0-sun-plugin-1.6.0.75-1jpp.3.el5_10.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 7e93bbd5b0e542fd38006d56d660adb5
SHA-256: 50d5d8d4481d91cdcb506db5f215866708240d22afbfd883f6e52ad1a707e2d4
java-1.6.0-sun-src-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: 1ce8c407b4762d6a36b79b6f53500f48
SHA-256: fb06abede2559681e946611f19f3212d8865011fcd3579643baa591d49350b98
java-1.6.0-sun-src-1.6.0.75-1jpp.3.el5_10.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: e90c80e08851dc689ff2cae4bba4d5f9
SHA-256: 5a1a4ee33683748fb4d3178b03cf88147613752092f06f11969acb8297d27df5
 
Oracle Java for RHEL Desktop (v. 5 client)

IA-32:
java-1.6.0-sun-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: cf976db889b1344ea652173f075b228f
SHA-256: 31f5a47d78ca71e9bab6c8c49cf2e5a97a5c90ba53fea06e16dd45b69f403273
java-1.6.0-sun-demo-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: 7c0553a103cf4c6499f739d0599395b9
SHA-256: ea2308b884f187d8ca933bee51f138a32a226bd7b57161641f16d3dae9f29c00
java-1.6.0-sun-devel-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: 57ce767c5f8ef1259e954a2a66cd628b
SHA-256: a6c36982b938047ffe277fe5c092754fe9be65fdf64c35e37d864a68448a8758
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: e4c041c6d3d1b071434b4f286c9edf92
SHA-256: a4a3234d882671b4082fb494f34d6c80086635304b74992a23fd5ece7960b3d0
java-1.6.0-sun-plugin-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: c88e399a73b30e96172b43df3eef171b
SHA-256: aae82f962f097b141de308ca11032f3ee1fa34657691cb28dcb0dae7775554aa
java-1.6.0-sun-src-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: 1ce8c407b4762d6a36b79b6f53500f48
SHA-256: fb06abede2559681e946611f19f3212d8865011fcd3579643baa591d49350b98
 
x86_64:
java-1.6.0-sun-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: cf976db889b1344ea652173f075b228f
SHA-256: 31f5a47d78ca71e9bab6c8c49cf2e5a97a5c90ba53fea06e16dd45b69f403273
java-1.6.0-sun-1.6.0.75-1jpp.3.el5_10.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 87ff30ab10114ea706dfb4428948e4fe
SHA-256: 40b5d9bb265c5cdd16b080516d7b6eec9f6477f6c74dd16032a1253c694658d5
java-1.6.0-sun-demo-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: 7c0553a103cf4c6499f739d0599395b9
SHA-256: ea2308b884f187d8ca933bee51f138a32a226bd7b57161641f16d3dae9f29c00
java-1.6.0-sun-demo-1.6.0.75-1jpp.3.el5_10.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 0c2bf48a75976bcc99be725aed95247f
SHA-256: d89e95633f5471c7d99b81b459bbb8ff59e0cc091574e9e88703007d090ba20e
java-1.6.0-sun-devel-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: 57ce767c5f8ef1259e954a2a66cd628b
SHA-256: a6c36982b938047ffe277fe5c092754fe9be65fdf64c35e37d864a68448a8758
java-1.6.0-sun-devel-1.6.0.75-1jpp.3.el5_10.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 732259beddf2d51d0f7f713093695b11
SHA-256: 1614fd8eafd6b1cca5f6d9a22b12ac6a68a6f8f9e0624898ff9ca56425e77dd5
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: e4c041c6d3d1b071434b4f286c9edf92
SHA-256: a4a3234d882671b4082fb494f34d6c80086635304b74992a23fd5ece7960b3d0
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.3.el5_10.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: f4e0877aab74f8050f3d08dfc27ee6c4
SHA-256: 83647228f8a4fa8c0ec9f0d24cd5b85b0ea3619b09ceef22e22fdfb61644fb9b
java-1.6.0-sun-plugin-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: c88e399a73b30e96172b43df3eef171b
SHA-256: aae82f962f097b141de308ca11032f3ee1fa34657691cb28dcb0dae7775554aa
java-1.6.0-sun-plugin-1.6.0.75-1jpp.3.el5_10.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 7e93bbd5b0e542fd38006d56d660adb5
SHA-256: 50d5d8d4481d91cdcb506db5f215866708240d22afbfd883f6e52ad1a707e2d4
java-1.6.0-sun-src-1.6.0.75-1jpp.3.el5_10.i586.rpm
File outdated by:  RHSA-2015:0858
    MD5: 1ce8c407b4762d6a36b79b6f53500f48
SHA-256: fb06abede2559681e946611f19f3212d8865011fcd3579643baa591d49350b98
java-1.6.0-sun-src-1.6.0.75-1jpp.3.el5_10.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: e90c80e08851dc689ff2cae4bba4d5f9
SHA-256: 5a1a4ee33683748fb4d3178b03cf88147613752092f06f11969acb8297d27df5
 
Oracle Java for Red Hat Enterprise Linux Desktop (v. 6)

IA-32:
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: db952f5189ce1a625d0b949cad12a649
SHA-256: 5045c27465c008e6446d5ac53db37918554762ab51f2cced21a17a59ea7f3732
java-1.6.0-sun-demo-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: a43fa891c3c59834504dc14fced13d80
SHA-256: 2fa30395744cbd466737948d076e2ba0b63b024008f8c1bfbd1f4a74addcd0ab
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 8e77cfebc3ea9dddf159eb428a48eff7
SHA-256: 13f0d212c68d1f785e7c05c771fa471a86af631256f0fedbdf08b17323de424b
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 91f09999fdccb19674ef570cff17b8fb
SHA-256: 5b418e3fdcea182efb8c1a85b0902d719f3273d9f68303d49d94c46400c9547e
java-1.6.0-sun-plugin-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 046741748bb67ea54e789760939093ba
SHA-256: b437af6ad33d248dd72137be69bc6b462d24088f8e4b85803344ca8f067104d7
java-1.6.0-sun-src-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 417aefe6aa9b9334785660ccf8f5dffd
SHA-256: 4cb41573271f65e335422f6c13bd8e585fdf9fb9ed2c4da7b4b3c44e6c9042fc
 
x86_64:
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: db952f5189ce1a625d0b949cad12a649
SHA-256: 5045c27465c008e6446d5ac53db37918554762ab51f2cced21a17a59ea7f3732
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 66763e020d6349cf340315e131ff30f4
SHA-256: 62301e009532b693a7648026a8a51db8c8e4c30f61e54184ec197b57eb419024
java-1.6.0-sun-demo-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 53f4ca2c75d3d59de2eeb8f07fc63504
SHA-256: 702f6bb7696c010313d83252122272615eec75e0b92696ec215b48cef224b4ec
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 8e77cfebc3ea9dddf159eb428a48eff7
SHA-256: 13f0d212c68d1f785e7c05c771fa471a86af631256f0fedbdf08b17323de424b
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 1b8dc24263e939b2367658d41887830e
SHA-256: 2d3d19e9754ffdc661b895abf70cd117c59c18a20dc68ef1ef122ebada16093f
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 11cda340e1b7f0e572261eabf92f3784
SHA-256: 81d5a3850158d436f2f882c6305e13d7e8937a5b6beea95b2356f7f4ac9f4878
java-1.6.0-sun-plugin-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 352757634b8cd42132fbd9cea581205c
SHA-256: 0ed9cec8a237f8bc6b70edf9b0bb523b005988cda7af2ce58db2a3e754941d44
java-1.6.0-sun-src-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: ac78102dc2325ee65b8fede6d8e02779
SHA-256: 8e7aeac019017725d591591f163c18519a6b5d133e870a58b2cd21cbaf5b4968
 
Oracle Java for Red Hat Enterprise Linux HPC Node (v. 6)

x86_64:
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: db952f5189ce1a625d0b949cad12a649
SHA-256: 5045c27465c008e6446d5ac53db37918554762ab51f2cced21a17a59ea7f3732
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 66763e020d6349cf340315e131ff30f4
SHA-256: 62301e009532b693a7648026a8a51db8c8e4c30f61e54184ec197b57eb419024
java-1.6.0-sun-demo-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 53f4ca2c75d3d59de2eeb8f07fc63504
SHA-256: 702f6bb7696c010313d83252122272615eec75e0b92696ec215b48cef224b4ec
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 8e77cfebc3ea9dddf159eb428a48eff7
SHA-256: 13f0d212c68d1f785e7c05c771fa471a86af631256f0fedbdf08b17323de424b
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 1b8dc24263e939b2367658d41887830e
SHA-256: 2d3d19e9754ffdc661b895abf70cd117c59c18a20dc68ef1ef122ebada16093f
java-1.6.0-sun-src-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: ac78102dc2325ee65b8fede6d8e02779
SHA-256: 8e7aeac019017725d591591f163c18519a6b5d133e870a58b2cd21cbaf5b4968
 
Oracle Java for Red Hat Enterprise Linux Server (v. 6)

IA-32:
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: db952f5189ce1a625d0b949cad12a649
SHA-256: 5045c27465c008e6446d5ac53db37918554762ab51f2cced21a17a59ea7f3732
java-1.6.0-sun-demo-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: a43fa891c3c59834504dc14fced13d80
SHA-256: 2fa30395744cbd466737948d076e2ba0b63b024008f8c1bfbd1f4a74addcd0ab
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 8e77cfebc3ea9dddf159eb428a48eff7
SHA-256: 13f0d212c68d1f785e7c05c771fa471a86af631256f0fedbdf08b17323de424b
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 91f09999fdccb19674ef570cff17b8fb
SHA-256: 5b418e3fdcea182efb8c1a85b0902d719f3273d9f68303d49d94c46400c9547e
java-1.6.0-sun-plugin-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 046741748bb67ea54e789760939093ba
SHA-256: b437af6ad33d248dd72137be69bc6b462d24088f8e4b85803344ca8f067104d7
java-1.6.0-sun-src-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 417aefe6aa9b9334785660ccf8f5dffd
SHA-256: 4cb41573271f65e335422f6c13bd8e585fdf9fb9ed2c4da7b4b3c44e6c9042fc
 
x86_64:
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: db952f5189ce1a625d0b949cad12a649
SHA-256: 5045c27465c008e6446d5ac53db37918554762ab51f2cced21a17a59ea7f3732
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 66763e020d6349cf340315e131ff30f4
SHA-256: 62301e009532b693a7648026a8a51db8c8e4c30f61e54184ec197b57eb419024
java-1.6.0-sun-demo-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 53f4ca2c75d3d59de2eeb8f07fc63504
SHA-256: 702f6bb7696c010313d83252122272615eec75e0b92696ec215b48cef224b4ec
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 8e77cfebc3ea9dddf159eb428a48eff7
SHA-256: 13f0d212c68d1f785e7c05c771fa471a86af631256f0fedbdf08b17323de424b
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 1b8dc24263e939b2367658d41887830e
SHA-256: 2d3d19e9754ffdc661b895abf70cd117c59c18a20dc68ef1ef122ebada16093f
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 11cda340e1b7f0e572261eabf92f3784
SHA-256: 81d5a3850158d436f2f882c6305e13d7e8937a5b6beea95b2356f7f4ac9f4878
java-1.6.0-sun-plugin-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 352757634b8cd42132fbd9cea581205c
SHA-256: 0ed9cec8a237f8bc6b70edf9b0bb523b005988cda7af2ce58db2a3e754941d44
java-1.6.0-sun-src-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: ac78102dc2325ee65b8fede6d8e02779
SHA-256: 8e7aeac019017725d591591f163c18519a6b5d133e870a58b2cd21cbaf5b4968
 
Oracle Java for Red Hat Enterprise Linux Server AUS (v. 6.5)

x86_64:
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2014:0908
    MD5: db952f5189ce1a625d0b949cad12a649
SHA-256: 5045c27465c008e6446d5ac53db37918554762ab51f2cced21a17a59ea7f3732
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2014:0908
    MD5: 66763e020d6349cf340315e131ff30f4
SHA-256: 62301e009532b693a7648026a8a51db8c8e4c30f61e54184ec197b57eb419024
java-1.6.0-sun-demo-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2014:0908
    MD5: 53f4ca2c75d3d59de2eeb8f07fc63504
SHA-256: 702f6bb7696c010313d83252122272615eec75e0b92696ec215b48cef224b4ec
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2014:0908
    MD5: 8e77cfebc3ea9dddf159eb428a48eff7
SHA-256: 13f0d212c68d1f785e7c05c771fa471a86af631256f0fedbdf08b17323de424b
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2014:0908
    MD5: 1b8dc24263e939b2367658d41887830e
SHA-256: 2d3d19e9754ffdc661b895abf70cd117c59c18a20dc68ef1ef122ebada16093f
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2014:0908
    MD5: 11cda340e1b7f0e572261eabf92f3784
SHA-256: 81d5a3850158d436f2f882c6305e13d7e8937a5b6beea95b2356f7f4ac9f4878
java-1.6.0-sun-plugin-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2014:0908
    MD5: 352757634b8cd42132fbd9cea581205c
SHA-256: 0ed9cec8a237f8bc6b70edf9b0bb523b005988cda7af2ce58db2a3e754941d44
java-1.6.0-sun-src-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2014:0908
    MD5: ac78102dc2325ee65b8fede6d8e02779
SHA-256: 8e7aeac019017725d591591f163c18519a6b5d133e870a58b2cd21cbaf5b4968
 
Oracle Java for Red Hat Enterprise Linux Server EUS (v. 6.5.z)

IA-32:
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2014:0908
    MD5: db952f5189ce1a625d0b949cad12a649
SHA-256: 5045c27465c008e6446d5ac53db37918554762ab51f2cced21a17a59ea7f3732
java-1.6.0-sun-demo-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2014:0908
    MD5: a43fa891c3c59834504dc14fced13d80
SHA-256: 2fa30395744cbd466737948d076e2ba0b63b024008f8c1bfbd1f4a74addcd0ab
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2014:0908
    MD5: 8e77cfebc3ea9dddf159eb428a48eff7
SHA-256: 13f0d212c68d1f785e7c05c771fa471a86af631256f0fedbdf08b17323de424b
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2014:0908
    MD5: 91f09999fdccb19674ef570cff17b8fb
SHA-256: 5b418e3fdcea182efb8c1a85b0902d719f3273d9f68303d49d94c46400c9547e
java-1.6.0-sun-plugin-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2014:0908
    MD5: 046741748bb67ea54e789760939093ba
SHA-256: b437af6ad33d248dd72137be69bc6b462d24088f8e4b85803344ca8f067104d7
java-1.6.0-sun-src-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2014:0908
    MD5: 417aefe6aa9b9334785660ccf8f5dffd
SHA-256: 4cb41573271f65e335422f6c13bd8e585fdf9fb9ed2c4da7b4b3c44e6c9042fc
 
x86_64:
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2014:0908
    MD5: db952f5189ce1a625d0b949cad12a649
SHA-256: 5045c27465c008e6446d5ac53db37918554762ab51f2cced21a17a59ea7f3732
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2014:0908
    MD5: 66763e020d6349cf340315e131ff30f4
SHA-256: 62301e009532b693a7648026a8a51db8c8e4c30f61e54184ec197b57eb419024
java-1.6.0-sun-demo-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2014:0908
    MD5: 53f4ca2c75d3d59de2eeb8f07fc63504
SHA-256: 702f6bb7696c010313d83252122272615eec75e0b92696ec215b48cef224b4ec
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2014:0908
    MD5: 8e77cfebc3ea9dddf159eb428a48eff7
SHA-256: 13f0d212c68d1f785e7c05c771fa471a86af631256f0fedbdf08b17323de424b
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2014:0908
    MD5: 1b8dc24263e939b2367658d41887830e
SHA-256: 2d3d19e9754ffdc661b895abf70cd117c59c18a20dc68ef1ef122ebada16093f
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2014:0908
    MD5: 11cda340e1b7f0e572261eabf92f3784
SHA-256: 81d5a3850158d436f2f882c6305e13d7e8937a5b6beea95b2356f7f4ac9f4878
java-1.6.0-sun-plugin-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2014:0908
    MD5: 352757634b8cd42132fbd9cea581205c
SHA-256: 0ed9cec8a237f8bc6b70edf9b0bb523b005988cda7af2ce58db2a3e754941d44
java-1.6.0-sun-src-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2014:0908
    MD5: ac78102dc2325ee65b8fede6d8e02779
SHA-256: 8e7aeac019017725d591591f163c18519a6b5d133e870a58b2cd21cbaf5b4968
 
Oracle Java for Red Hat Enterprise Linux Workstation (v. 6)

IA-32:
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: db952f5189ce1a625d0b949cad12a649
SHA-256: 5045c27465c008e6446d5ac53db37918554762ab51f2cced21a17a59ea7f3732
java-1.6.0-sun-demo-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: a43fa891c3c59834504dc14fced13d80
SHA-256: 2fa30395744cbd466737948d076e2ba0b63b024008f8c1bfbd1f4a74addcd0ab
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 8e77cfebc3ea9dddf159eb428a48eff7
SHA-256: 13f0d212c68d1f785e7c05c771fa471a86af631256f0fedbdf08b17323de424b
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 91f09999fdccb19674ef570cff17b8fb
SHA-256: 5b418e3fdcea182efb8c1a85b0902d719f3273d9f68303d49d94c46400c9547e
java-1.6.0-sun-plugin-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 046741748bb67ea54e789760939093ba
SHA-256: b437af6ad33d248dd72137be69bc6b462d24088f8e4b85803344ca8f067104d7
java-1.6.0-sun-src-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 417aefe6aa9b9334785660ccf8f5dffd
SHA-256: 4cb41573271f65e335422f6c13bd8e585fdf9fb9ed2c4da7b4b3c44e6c9042fc
 
x86_64:
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: db952f5189ce1a625d0b949cad12a649
SHA-256: 5045c27465c008e6446d5ac53db37918554762ab51f2cced21a17a59ea7f3732
java-1.6.0-sun-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 66763e020d6349cf340315e131ff30f4
SHA-256: 62301e009532b693a7648026a8a51db8c8e4c30f61e54184ec197b57eb419024
java-1.6.0-sun-demo-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 53f4ca2c75d3d59de2eeb8f07fc63504
SHA-256: 702f6bb7696c010313d83252122272615eec75e0b92696ec215b48cef224b4ec
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.i686.rpm
File outdated by:  RHSA-2015:0858
    MD5: 8e77cfebc3ea9dddf159eb428a48eff7
SHA-256: 13f0d212c68d1f785e7c05c771fa471a86af631256f0fedbdf08b17323de424b
java-1.6.0-sun-devel-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 1b8dc24263e939b2367658d41887830e
SHA-256: 2d3d19e9754ffdc661b895abf70cd117c59c18a20dc68ef1ef122ebada16093f
java-1.6.0-sun-jdbc-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 11cda340e1b7f0e572261eabf92f3784
SHA-256: 81d5a3850158d436f2f882c6305e13d7e8937a5b6beea95b2356f7f4ac9f4878
java-1.6.0-sun-plugin-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: 352757634b8cd42132fbd9cea581205c
SHA-256: 0ed9cec8a237f8bc6b70edf9b0bb523b005988cda7af2ce58db2a3e754941d44
java-1.6.0-sun-src-1.6.0.75-1jpp.1.el6_5.x86_64.rpm
File outdated by:  RHSA-2015:0858
    MD5: ac78102dc2325ee65b8fede6d8e02779
SHA-256: 8e7aeac019017725d591591f163c18519a6b5d133e870a58b2cd21cbaf5b4968
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

1018713 - CVE-2013-5803 OpenJDK: insufficient checks of KDC replies (JGSS, 8014341)
1018717 - CVE-2013-5772 OpenJDK: insufficient html escaping in jhat (jhat, 8011081)
1018720 - CVE-2013-5797 OpenJDK: insufficient escaping of window title string (Javadoc, 8016675)
1018727 - CVE-2013-5784 OpenJDK: insufficient InterfaceImplementor security checks (Scripting, 8017299)
1018736 - CVE-2013-5790 OpenJDK: insufficient security checks (Beans, 8012071)
1018750 - CVE-2013-5849 OpenJDK: insufficient DataFlavor security checks (AWT, 8012277)
1018785 - CVE-2013-5780 OpenJDK: key data leak via toString() methods (Libraries, 8011071)
1018831 - CVE-2013-5840 OpenJDK: getDeclaringClass() information leak (Libraries, 8014349)
1018972 - CVE-2013-5820 OpenJDK: insufficient security checks (JAXWS, 8017505)
1018984 - CVE-2013-5778 OpenJDK: image conversion out of bounds read (2D, 8014102)
1019108 - CVE-2013-5782 OpenJDK: Incorrect awt_getPixelByte/awt_getPixelShort/awt_setPixelByte/awt_setPixelShort image raster checks (2D, 8014093)
1019110 - CVE-2013-5830 OpenJDK: checkPackageAccess missing security check (Libraries, 8017291)
1019113 - CVE-2013-5809 OpenJDK: JPEGImageReader and JPEGImageWriter missing band size checks (2D, 8013510)
1019115 - CVE-2013-5829 OpenJDK: Java2d Disposer security bypass (2D, 8017287)
1019117 - CVE-2013-5814 OpenJDK: RMIConnection stub missing permission check (CORBA, 8011157)
1019118 - CVE-2013-5817 OpenJDK: VersionHelper12 does not honor modifyThreadGroup restriction (JNDI, 8013739)
1019123 - CVE-2013-5842 OpenJDK: ObjectInputStream/ObjectOutputStream missing checks (Libraries, 8014987)
1019127 - CVE-2013-5850 OpenJDK: Missing CORBA security checks (Libraries, 8017196)
1019130 - CVE-2013-5802 OpenJDK: javax.xml.transform.TransformerFactory does not properly honor XMLConstants.FEATURE_SECURE_PROCESSING (JAXP, 8012425)
1019131 - CVE-2013-5804 OpenJDK: javac does not ignore certain ignorable characters (Javadoc, 8016653)
1019133 - CVE-2013-3829 OpenJDK: java.util.TimeZone does not restrict setting of default time zone (Libraries, 8001029)
1019137 - CVE-2013-5783 OpenJDK: JTable not properly performing certain access checks (Swing, 8013744)
1019139 - CVE-2013-5825 OpenJDK: XML parsing Denial of Service (JAXP, 8014530)
1019145 - CVE-2013-5823 OpenJDK: com.sun.org.apache.xml.internal.security.utils.UnsyncByteArrayOutputStream Denial of Service (Security, 8021290)
1019147 - CVE-2013-5774 OpenJDK: Inet6Address class IPv6 address processing errors (Libraries, 8015743)
1019176 - CVE-2013-4002 OpenJDK: XML parsing Denial of Service (JAXP, 8017298)
1019691 - CVE-2013-5824 Oracle JDK: unspecified vulnerability fixed in 7u45 (Deployment)
1019693 - CVE-2013-5787 Oracle JDK: unspecified vulnerability fixed in 7u45 (Deployment)
1019697 - CVE-2013-5789 Oracle JDK: unspecified vulnerability fixed in 7u45 (Deployment)
1019701 - CVE-2013-5843 Oracle JDK: unspecified vulnerability fixed in 7u45 (2D)
1019702 - CVE-2013-5832 Oracle JDK: unspecified vulnerability fixed in 7u45 (Deployment)
1019705 - CVE-2013-5852 Oracle JDK: unspecified vulnerability fixed in 7u45 (Deployment)
1019706 - CVE-2013-5812 Oracle JDK: unspecified vulnerability fixed in 7u45 (Deployment)
1019710 - CVE-2013-5801 Oracle JDK: unspecified vulnerability fixed in 7u45 (2D)
1019712 - CVE-2013-5776 Oracle JDK: unspecified vulnerability fixed in 7u45 (Deployment)
1019713 - CVE-2013-5818 Oracle JDK: unspecified vulnerability fixed in 7u45 (Deployment)
1019715 - CVE-2013-5819 Oracle JDK: unspecified vulnerability fixed in 7u45 (Deployment)
1019716 - CVE-2013-5831 Oracle JDK: unspecified vulnerability fixed in 7u45 (Deployment)
1019720 - CVE-2013-5848 Oracle JDK: unspecified vulnerability fixed in 7u45 (Deployment)
1031734 - CVE-2013-6629 libjpeg: information leak (read of uninitialized memory)
1045561 - CVE-2013-6954 libpng: unhandled zero-length PLTE chunk or NULL palette
1051519 - CVE-2014-0428 OpenJDK: insufficient security checks in IIOP streams (CORBA, 8025767)
1051528 - CVE-2014-0422 OpenJDK: insufficient package access checks in the Naming component (JNDI, 8025758)
1051699 - CVE-2014-0373 OpenJDK: SnmpStatusException handling issues (Serviceability, 7068126)
1051823 - CVE-2013-5878 OpenJDK: null xmlns handling issue (Security, 8025026)
1051911 - CVE-2013-5884 OpenJDK: insufficient security checks in CORBA stub factories (CORBA, 8026193)
1051912 - CVE-2014-0416 OpenJDK: insecure subject principals set handling (JAAS, 8024306)
1051923 - CVE-2014-0376 OpenJDK: document builder missing security checks (JAXP, 8027201, 8025018)
1052915 - CVE-2013-5907 ICU: Layout Engine LookupProcessor insufficient input checks (JDK 2D, 8025034)
1052919 - CVE-2014-0368 OpenJDK: insufficient Socket checkListen checks (Networking, 8011786)
1052942 - CVE-2013-5910 OpenJDK: XML canonicalizer mutable strings passed to untrusted code (Security, 8026417)
1053010 - CVE-2014-0411 OpenJDK: TLS/SSL handshake timing issues (JSSE, 8023069)
1053066 - CVE-2014-0423 OpenJDK: XXE issue in decoder (Beans, 8023245)
1053266 - CVE-2013-5896 OpenJDK: com.sun.corba.se. should be restricted package (CORBA, 8025022)
1053495 - CVE-2014-0410 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
1053496 - CVE-2014-0415 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
1053499 - CVE-2013-5889 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
1053501 - CVE-2014-0417 Oracle JDK: unspecified vulnerability fixed in 5.0u71, 6u71 and 7u51 (2D)
1053502 - CVE-2014-0387 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
1053504 - CVE-2014-0424 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
1053507 - CVE-2014-0403 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
1053508 - CVE-2014-0375 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
1053509 - CVE-2013-5905 Oracle JDK: unspecified vulnerability fixed in 5.0u71, 6u71 and 7u51 (Install)
1053510 - CVE-2013-5906 Oracle JDK: unspecified vulnerability fixed in 5.0u71, 6u71 and 7u51 (Install)
1053512 - CVE-2013-5902 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
1053513 - CVE-2014-0418 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
1053515 - CVE-2013-5887 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
1053516 - CVE-2013-5899 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
1053517 - CVE-2013-5888 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
1053518 - CVE-2013-5898 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
1060907 - CVE-2014-1876 OpenJDK: insecure temporary file use in unpack200 (Libraries, 8033618)
1086632 - CVE-2014-2398 OpenJDK: insufficient escaping of window title string (Javadoc, 8026736)
1086645 - CVE-2014-0453 OpenJDK: RSA unpadding timing issues (Security, 8027766)
1087409 - CVE-2014-0429 OpenJDK: Incorrect mlib/raster image validation (2D, 8027841)
1087411 - CVE-2014-0457 OpenJDK: ServiceLoader Exception handling security bypass (Libraries, 8031394)
1087413 - CVE-2014-0456 OpenJDK: System.arraycopy() element race condition (Hotspot, 8029858)
1087417 - CVE-2014-2421 OpenJDK: JPEG decoder input stream handling (2D, 8029854)
1087426 - CVE-2014-0461 OpenJDK: Better ScriptEngineManager ScriptEngine management (Libraries, 8036794)
1087427 - CVE-2014-2412 OpenJDK: AWT thread context handling (AWT, 8025010)
1087428 - CVE-2014-0451 OpenJDK: AWT incorrect FlavorMap seperation (AWT, 8026797)
1087430 - CVE-2014-0458 OpenJDK: Activation framework default command map caching (JAX-WS, 8025152)
1087431 - CVE-2014-2414 OpenJDK: incorrect caching of data initialized via TCCL (JAXB, 8025030)
1087434 - CVE-2014-2423 OpenJDK: incorrect caching of data initialized via TCCL (JAXWS, 8026188)
1087436 - CVE-2014-0452 OpenJDK: incorrect caching of data initialized via TCCL (JAXWS, 8026801)
1087439 - CVE-2014-0446 OpenJDK: Protect logger handlers (Libraries, 8029740)
1087441 - CVE-2014-2427 OpenJDK: remove insecure Java Sound provider caching (Sound, 8026163)
1087442 - CVE-2014-0460 OpenJDK: missing randomization of JNDI DNS client query IDs (JNDI, 8030731)
1087443 - CVE-2014-2403 OpenJDK: JAXP CharInfo file access restriction (JAXP, 8029282)
1088025 - CVE-2014-2428 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
1088027 - CVE-2014-2409 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
1088028 - CVE-2014-0449 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
1088030 - CVE-2014-2401 Oracle JDK: unspecified vulnerability fixed in 5.0u75, 6u75, 7u55 and 8u5 (2D)
1088031 - CVE-2014-2420 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
973474 - CVE-2013-1571 OpenJDK: Frame injection in generated HTML (Javadoc, 8012375)
975099 - CVE-2013-2470 OpenJDK: ImagingLib byte lookup processing (2D, 8011243)
975102 - CVE-2013-2471 OpenJDK: Incorrect IntegerComponentRaster size checks (2D, 8011248)
975107 - CVE-2013-2472 OpenJDK: Incorrect ShortBandedRaster size checks (2D, 8011253)
975110 - CVE-2013-2473 OpenJDK: Incorrect ByteBandedRaster size checks (2D, 8011257)
975115 - CVE-2013-2463 OpenJDK: Incorrect image attribute verification (2D, 8012438)
975118 - CVE-2013-2465 OpenJDK: Incorrect image channel verification (2D, 8012597)
975120 - CVE-2013-2469 OpenJDK: Incorrect image layout verification (2D, 8012601)
975121 - CVE-2013-2459 OpenJDK: Various AWT integer overflow checks (AWT, 8009071)
975124 - CVE-2013-2445 OpenJDK: Better handling of memory allocation errors (Hotspot, 7158805)
975125 - CVE-2013-2448 OpenJDK: Better access restrictions (Sound, 8006328)
975126 - CVE-2013-2461 OpenJDK: Missing check for valid DOMCanonicalizationMethod canonicalization algorithm (Libraries, 8014281)
975127 - CVE-2013-2407 OpenJDK: Integrate Apache Santuario, rework class loader (Libraries, 6741606, 8008744)
975129 - CVE-2013-2454 OpenJDK: SerialJavaObject package restriction (JDBC, 8009554)
975131 - CVE-2013-2444 OpenJDK: Resource denial of service (AWT, 8001038)
975132 - CVE-2013-2446 OpenJDK: output stream access restrictions (CORBA, 8000642)
975133 - CVE-2013-2457 OpenJDK: Proper class checking (JMX, 8008120)
975134 - CVE-2013-2453 OpenJDK: MBeanServer Introspector package access (JMX, 8008124)
975137 - CVE-2013-2443 OpenJDK: AccessControlContext check order issue (Libraries, 8001330)
975138 - CVE-2013-2452 OpenJDK: Unique VMIDs (Libraries, 8001033)
975139 - CVE-2013-2455 OpenJDK: getEnclosing* checks (Libraries, 8007812)
975140 - CVE-2013-2447 OpenJDK: Prevent revealing the local address (Networking, 8001318)
975141 - CVE-2013-2450 OpenJDK: ObjectStreamClass circular reference denial of service (Serialization, 8000638)
975142 - CVE-2013-2456 OpenJDK: ObjectOutputStream access checks (Serialization, 8008132)
975144 - CVE-2013-2412 OpenJDK: JConsole SSL support (Serviceability, 8003703)
975146 - CVE-2013-2451 OpenJDK: exclusive port binding (Networking, 7170730)
975148 - CVE-2013-1500 OpenJDK: Insecure shared memory permissions (2D, 8001034)
975757 - CVE-2013-2464 Oracle JDK: unspecified vulnerability fixed in 7u25 (2D)
975761 - CVE-2013-2468 Oracle JDK: unspecified vulnerability fixed in 7u25 (Deployment)
975764 - CVE-2013-2466 Oracle JDK: unspecified vulnerability fixed in 7u25 (Deployment)
975767 - CVE-2013-3743 Oracle JDK: unspecified vulnerability fixed in 6u51 and 5u51 (AWT)
975770 - CVE-2013-2442 Oracle JDK: unspecified vulnerability fixed in 7u25 (Deployment)
975773 - CVE-2013-2437 Oracle JDK: unspecified vulnerability fixed in 7u25 (Deployment)


References

https://www.redhat.com/security/data/cve/CVE-2013-1500.html
https://www.redhat.com/security/data/cve/CVE-2013-1571.html
https://www.redhat.com/security/data/cve/CVE-2013-2407.html
https://www.redhat.com/security/data/cve/CVE-2013-2412.html
https://www.redhat.com/security/data/cve/CVE-2013-2437.html
https://www.redhat.com/security/data/cve/CVE-2013-2442.html
https://www.redhat.com/security/data/cve/CVE-2013-2443.html
https://www.redhat.com/security/data/cve/CVE-2013-2444.html
https://www.redhat.com/security/data/cve/CVE-2013-2445.html
https://www.redhat.com/security/data/cve/CVE-2013-2446.html
https://www.redhat.com/security/data/cve/CVE-2013-2447.html
https://www.redhat.com/security/data/cve/CVE-2013-2448.html
https://www.redhat.com/security/data/cve/CVE-2013-2450.html
https://www.redhat.com/security/data/cve/CVE-2013-2451.html
https://www.redhat.com/security/data/cve/CVE-2013-2452.html
https://www.redhat.com/security/data/cve/CVE-2013-2453.html
https://www.redhat.com/security/data/cve/CVE-2013-2454.html
https://www.redhat.com/security/data/cve/CVE-2013-2455.html
https://www.redhat.com/security/data/cve/CVE-2013-2456.html
https://www.redhat.com/security/data/cve/CVE-2013-2457.html
https://www.redhat.com/security/data/cve/CVE-2013-2459.html
https://www.redhat.com/security/data/cve/CVE-2013-2461.html
https://www.redhat.com/security/data/cve/CVE-2013-2463.html
https://www.redhat.com/security/data/cve/CVE-2013-2464.html
https://www.redhat.com/security/data/cve/CVE-2013-2465.html
https://www.redhat.com/security/data/cve/CVE-2013-2466.html
https://www.redhat.com/security/data/cve/CVE-2013-2468.html
https://www.redhat.com/security/data/cve/CVE-2013-2469.html
https://www.redhat.com/security/data/cve/CVE-2013-2470.html
https://www.redhat.com/security/data/cve/CVE-2013-2471.html
https://www.redhat.com/security/data/cve/CVE-2013-2472.html
https://www.redhat.com/security/data/cve/CVE-2013-2473.html
https://www.redhat.com/security/data/cve/CVE-2013-3743.html
https://www.redhat.com/security/data/cve/CVE-2013-3829.html
https://www.redhat.com/security/data/cve/CVE-2013-4002.html
https://www.redhat.com/security/data/cve/CVE-2013-5772.html
https://www.redhat.com/security/data/cve/CVE-2013-5774.html
https://www.redhat.com/security/data/cve/CVE-2013-5776.html
https://www.redhat.com/security/data/cve/CVE-2013-5778.html
https://www.redhat.com/security/data/cve/CVE-2013-5780.html
https://www.redhat.com/security/data/cve/CVE-2013-5782.html
https://www.redhat.com/security/data/cve/CVE-2013-5783.html
https://www.redhat.com/security/data/cve/CVE-2013-5784.html
https://www.redhat.com/security/data/cve/CVE-2013-5787.html
https://www.redhat.com/security/data/cve/CVE-2013-5789.html
https://www.redhat.com/security/data/cve/CVE-2013-5790.html
https://www.redhat.com/security/data/cve/CVE-2013-5797.html
https://www.redhat.com/security/data/cve/CVE-2013-5801.html
https://www.redhat.com/security/data/cve/CVE-2013-5802.html
https://www.redhat.com/security/data/cve/CVE-2013-5803.html
https://www.redhat.com/security/data/cve/CVE-2013-5804.html
https://www.redhat.com/security/data/cve/CVE-2013-5809.html
https://www.redhat.com/security/data/cve/CVE-2013-5812.html
https://www.redhat.com/security/data/cve/CVE-2013-5814.html
https://www.redhat.com/security/data/cve/CVE-2013-5817.html
https://www.redhat.com/security/data/cve/CVE-2013-5818.html
https://www.redhat.com/security/data/cve/CVE-2013-5819.html
https://www.redhat.com/security/data/cve/CVE-2013-5820.html
https://www.redhat.com/security/data/cve/CVE-2013-5823.html
https://www.redhat.com/security/data/cve/CVE-2013-5824.html
https://www.redhat.com/security/data/cve/CVE-2013-5825.html
https://www.redhat.com/security/data/cve/CVE-2013-5829.html
https://www.redhat.com/security/data/cve/CVE-2013-5830.html
https://www.redhat.com/security/data/cve/CVE-2013-5831.html
https://www.redhat.com/security/data/cve/CVE-2013-5832.html
https://www.redhat.com/security/data/cve/CVE-2013-5840.html
https://www.redhat.com/security/data/cve/CVE-2013-5842.html
https://www.redhat.com/security/data/cve/CVE-2013-5843.html
https://www.redhat.com/security/data/cve/CVE-2013-5848.html
https://www.redhat.com/security/data/cve/CVE-2013-5849.html
https://www.redhat.com/security/data/cve/CVE-2013-5850.html
https://www.redhat.com/security/data/cve/CVE-2013-5852.html
https://www.redhat.com/security/data/cve/CVE-2013-5878.html
https://www.redhat.com/security/data/cve/CVE-2013-5884.html
https://www.redhat.com/security/data/cve/CVE-2013-5887.html
https://www.redhat.com/security/data/cve/CVE-2013-5888.html
https://www.redhat.com/security/data/cve/CVE-2013-5889.html
https://www.redhat.com/security/data/cve/CVE-2013-5896.html
https://www.redhat.com/security/data/cve/CVE-2013-5898.html
https://www.redhat.com/security/data/cve/CVE-2013-5899.html
https://www.redhat.com/security/data/cve/CVE-2013-5902.html
https://www.redhat.com/security/data/cve/CVE-2013-5905.html
https://www.redhat.com/security/data/cve/CVE-2013-5906.html
https://www.redhat.com/security/data/cve/CVE-2013-5907.html
https://www.redhat.com/security/data/cve/CVE-2013-5910.html
https://www.redhat.com/security/data/cve/CVE-2013-6629.html
https://www.redhat.com/security/data/cve/CVE-2013-6954.html
https://www.redhat.com/security/data/cve/CVE-2014-0368.html
https://www.redhat.com/security/data/cve/CVE-2014-0373.html
https://www.redhat.com/security/data/cve/CVE-2014-0375.html
https://www.redhat.com/security/data/cve/CVE-2014-0376.html
https://www.redhat.com/security/data/cve/CVE-2014-0387.html
https://www.redhat.com/security/data/cve/CVE-2014-0403.html
https://www.redhat.com/security/data/cve/CVE-2014-0410.html
https://www.redhat.com/security/data/cve/CVE-2014-0411.html
https://www.redhat.com/security/data/cve/CVE-2014-0415.html
https://www.redhat.com/security/data/cve/CVE-2014-0416.html
https://www.redhat.com/security/data/cve/CVE-2014-0417.html
https://www.redhat.com/security/data/cve/CVE-2014-0418.html
https://www.redhat.com/security/data/cve/CVE-2014-0422.html
https://www.redhat.com/security/data/cve/CVE-2014-0423.html
https://www.redhat.com/security/data/cve/CVE-2014-0424.html
https://www.redhat.com/security/data/cve/CVE-2014-0428.html
https://www.redhat.com/security/data/cve/CVE-2014-0429.html
https://www.redhat.com/security/data/cve/CVE-2014-0446.html
https://www.redhat.com/security/data/cve/CVE-2014-0449.html
https://www.redhat.com/security/data/cve/CVE-2014-0451.html
https://www.redhat.com/security/data/cve/CVE-2014-0452.html
https://www.redhat.com/security/data/cve/CVE-2014-0453.html
https://www.redhat.com/security/data/cve/CVE-2014-0456.html
https://www.redhat.com/security/data/cve/CVE-2014-0457.html
https://www.redhat.com/security/data/cve/CVE-2014-0458.html
https://www.redhat.com/security/data/cve/CVE-2014-0460.html
https://www.redhat.com/security/data/cve/CVE-2014-0461.html
https://www.redhat.com/security/data/cve/CVE-2014-1876.html
https://www.redhat.com/security/data/cve/CVE-2014-2398.html
https://www.redhat.com/security/data/cve/CVE-2014-2401.html
https://www.redhat.com/security/data/cve/CVE-2014-2403.html
https://www.redhat.com/security/data/cve/CVE-2014-2409.html
https://www.redhat.com/security/data/cve/CVE-2014-2412.html
https://www.redhat.com/security/data/cve/CVE-2014-2414.html
https://www.redhat.com/security/data/cve/CVE-2014-2420.html
https://www.redhat.com/security/data/cve/CVE-2014-2421.html
https://www.redhat.com/security/data/cve/CVE-2014-2423.html
https://www.redhat.com/security/data/cve/CVE-2014-2427.html
https://www.redhat.com/security/data/cve/CVE-2014-2428.html
https://access.redhat.com/security/updates/classification/#important
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/