Red Hat Security Advisory: java-1.6.0-ibm security update
🔗 CVE IDs covered (14)
📋 Description
CVE-2009-0217 — xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass CVE-2009-3555 — TLS: MITM attacks via session renegotiation CVE-2009-3865 — java-1.6.0-sun: ACE in JRE Deployment Toolkit (6869752) CVE-2009-3866 — java-1.6.0-sun: Privilege escalation in the Java Web Start Installer (6872824) CVE-2009-3867 — java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303) CVE-2009-3868 — java-1.6.0-sun: Privilege escalation via crafted image file due improper color profiles parsing (6862970) CVE-2009-3869 — OpenJDK JRE AWT setDifflCM stack overflow (6872357) CVE-2009-3871 — OpenJDK JRE AWT setBytePixels heap overflow (6872358) CVE-2009-3872 — JRE JPEG JFIF Decoder issue (6862969) CVE-2009-3873 — OpenJDK JPEG Image Writer quantization problem (6862968) CVE-2009-3874 — OpenJDK ImageI/O JPEG heap overflow (6874643) CVE-2009-3875 — OpenJDK MessageDigest.isEqual introduces timing attack vulnerabilities (6863503) CVE-2009-3876 — OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877 CVE-2009-3877 — OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2009:1694
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=533215
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttp://www.ibm.com/developerworks/java/jdk/alerts/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=530053
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=530057
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=530061
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=530062
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=530063
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=530067
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=532906
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=533211
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=533212
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=511915
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=533214
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2009/rhsa-2009_1694.json