RHSA-2009:1551 - Security Advisory
Moderate: java-1.4.2-ibm security update
Security Advisory: Moderate
Updated java-1.4.2-ibm packages that fix two security issues are now
available for Red Hat Enterprise Linux 4 and 5 for SAP.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
The IBM 1.4.2 SR13-FP2 Java release includes the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit.
This update fixes two vulnerabilities in the IBM Java 2 Runtime Environment
and the IBM Java 2 Software Development Kit. These vulnerabilities are
summarized on the IBM "Security alerts" page listed in the References
section. (CVE-2008-5349, CVE-2009-2625)
Warning: Do not install these java-1.4.2-ibm packages for SAP alongside the
java-1.4.2-ibm packages from the Red Hat Enterprise Linux Extras or
Supplementary channels on the Red Hat Network. Doing so could cause your
system to fail to update cleanly, among other possible problems.
All users of java-1.4.2-ibm for Red Hat Enterprise Linux 4 and 5 for SAP
are advised to upgrade to these updated packages, which contain the IBM
1.4.2 SR13-FP2 Java release. All running instances of IBM Java must be
restarted for this update to take effect.
Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.
This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
- Red Hat Enterprise Linux for SAP 5 x86_64
- Red Hat Enterprise Linux for SAP 4 x86_64
- Red Hat Enterprise Linux for SAP from RHUI 5 x86_64
- BZ - 472206 - CVE-2008-5349 OpenJDK RSA public key length denial-of-service (6497740)
- BZ - 512921 - CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701)
This erratum does not contain any packages.