- Issued:
- 2009-11-04
- Updated:
- 2009-11-04
RHSA-2009:1551 - Security Advisory
Synopsis
Moderate: java-1.4.2-ibm security update
Type/Severity
Security Advisory: Moderate
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated java-1.4.2-ibm packages that fix two security issues are now
available for Red Hat Enterprise Linux 4 and 5 for SAP.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
Description
The IBM 1.4.2 SR13-FP2 Java release includes the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit.
This update fixes two vulnerabilities in the IBM Java 2 Runtime Environment
and the IBM Java 2 Software Development Kit. These vulnerabilities are
summarized on the IBM "Security alerts" page listed in the References
section. (CVE-2008-5349, CVE-2009-2625)
Warning: Do not install these java-1.4.2-ibm packages for SAP alongside the
java-1.4.2-ibm packages from the Red Hat Enterprise Linux Extras or
Supplementary channels on the Red Hat Network. Doing so could cause your
system to fail to update cleanly, among other possible problems.
All users of java-1.4.2-ibm for Red Hat Enterprise Linux 4 and 5 for SAP
are advised to upgrade to these updated packages, which contain the IBM
1.4.2 SR13-FP2 Java release. All running instances of IBM Java must be
restarted for this update to take effect.
Solution
Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.
This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259
Affected Products
- Red Hat Enterprise Linux for SAP Applications for x86_64 5 x86_64
- Red Hat Enterprise Linux for SAP Applications for x86_64 4 x86_64
- Red Hat Enterprise Linux for SAP Applications for x86_64 from RHUI 5 x86_64
Fixes
- BZ - 472206 - CVE-2008-5349 OpenJDK RSA public key length denial-of-service (6497740)
- BZ - 512921 - CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701)
CVEs
Red Hat Enterprise Linux for SAP Applications for x86_64 5
SRPM | |
---|---|
x86_64 | |
java-1.4.2-ibm-1.4.2.13.2.sap-1jpp.4.el5_3.x86_64.rpm | SHA-256: 80d4e8a717e5817fd80313a8a90d9226a811a792abf964cbde71dabd58869d33 |
java-1.4.2-ibm-demo-1.4.2.13.2.sap-1jpp.4.el5_3.x86_64.rpm | SHA-256: 00b3e1e6e0df535d98f747c64a828882820b2b0ced1396e016bc043c9ab94ddd |
java-1.4.2-ibm-devel-1.4.2.13.2.sap-1jpp.4.el5_3.x86_64.rpm | SHA-256: cc8565aeb772c3bc3178ca1862afad4c177d6f3f3a2b517e8905c9c73f5f0324 |
java-1.4.2-ibm-javacomm-1.4.2.13.2.sap-1jpp.4.el5_3.x86_64.rpm | SHA-256: 2398b69e113295554f0dec39f07803f8044218c5b11122f7a096bba94718ad60 |
java-1.4.2-ibm-src-1.4.2.13.2.sap-1jpp.4.el5_3.x86_64.rpm | SHA-256: 4ae43a7c8dfa70e602f016736011a1fa9205659bf4246ecd729a2e82db2c5666 |
Red Hat Enterprise Linux for SAP Applications for x86_64 4
SRPM | |
---|---|
x86_64 |
Red Hat Enterprise Linux for SAP Applications for x86_64 from RHUI 5
SRPM | |
---|---|
x86_64 | |
java-1.4.2-ibm-1.4.2.13.2.sap-1jpp.4.el5_3.x86_64.rpm | SHA-256: 80d4e8a717e5817fd80313a8a90d9226a811a792abf964cbde71dabd58869d33 |
java-1.4.2-ibm-demo-1.4.2.13.2.sap-1jpp.4.el5_3.x86_64.rpm | SHA-256: 00b3e1e6e0df535d98f747c64a828882820b2b0ced1396e016bc043c9ab94ddd |
java-1.4.2-ibm-devel-1.4.2.13.2.sap-1jpp.4.el5_3.x86_64.rpm | SHA-256: cc8565aeb772c3bc3178ca1862afad4c177d6f3f3a2b517e8905c9c73f5f0324 |
java-1.4.2-ibm-javacomm-1.4.2.13.2.sap-1jpp.4.el5_3.x86_64.rpm | SHA-256: 2398b69e113295554f0dec39f07803f8044218c5b11122f7a096bba94718ad60 |
java-1.4.2-ibm-src-1.4.2.13.2.sap-1jpp.4.el5_3.x86_64.rpm | SHA-256: 4ae43a7c8dfa70e602f016736011a1fa9205659bf4246ecd729a2e82db2c5666 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.