LWN.net Logo

Scientific Linux alert SL-java-20130220 (java-1.6.0-openjdk)

From:  Pat Riehecky <riehecky@fnal.gov>
To:  "SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV" <SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV>
Subject:  Security ERRATA Important: java-1.6.0-openjdk on SL5.x i386/x86_64
Date:  Wed, 20 Feb 2013 13:16:29 -0600
Message-ID:  <5125210D.4050001@fnal.gov>
Archive-link:  Article, Thread

Synopsis: Important: java-1.6.0-openjdk security update Issue Date: 2013-02-20 CVE Numbers: CVE-2013-0169 CVE-2013-1486 -- An improper permission check issue was discovered in the JMX component in OpenJDK. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions. (CVE-2013-1486) It was discovered that OpenJDK leaked timing information when decrypting TLS/SSL protocol encrypted records when CBC-mode cipher suites were used. A remote attacker could possibly use this flaw to retrieve plain text from the encrypted packets by using a TLS/SSL server as a padding oracle. (CVE-2013-0169) This erratum also upgrades the OpenJDK package to IcedTea6 1.11.8. All running instances of OpenJDK Java must be restarted for the update to take effect. -- SL5 x86_64 java-1.6.0-openjdk-1.6.0.0-1.35.1.11.8.el5_9.x86_64.rpm java-1.6.0-openjdk-debuginfo-1.6.0.0-1.35.1.11.8.el5_9.x86_64.rpm java-1.6.0-openjdk-demo-1.6.0.0-1.35.1.11.8.el5_9.x86_64.rpm java-1.6.0-openjdk-devel-1.6.0.0-1.35.1.11.8.el5_9.x86_64.rpm java-1.6.0-openjdk-javadoc-1.6.0.0-1.35.1.11.8.el5_9.x86_64.rpm java-1.6.0-openjdk-src-1.6.0.0-1.35.1.11.8.el5_9.x86_64.rpm i386 java-1.6.0-openjdk-1.6.0.0-1.35.1.11.8.el5_9.i386.rpm java-1.6.0-openjdk-debuginfo-1.6.0.0-1.35.1.11.8.el5_9.i386.rpm java-1.6.0-openjdk-demo-1.6.0.0-1.35.1.11.8.el5_9.i386.rpm java-1.6.0-openjdk-devel-1.6.0.0-1.35.1.11.8.el5_9.i386.rpm java-1.6.0-openjdk-javadoc-1.6.0.0-1.35.1.11.8.el5_9.i386.rpm java-1.6.0-openjdk-src-1.6.0.0-1.35.1.11.8.el5_9.i386.rpm - Scientific Linux Development Team


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds