RHSA-2009:1694Critical

Red Hat Security Advisory: java-1.6.0-ibm security update

Published
December 23, 2009
Last Modified
May 27, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2009-0217 — xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass CVE-2009-3555 — TLS: MITM attacks via session renegotiation CVE-2009-3865 — java-1.6.0-sun: ACE in JRE Deployment Toolkit (6869752) CVE-2009-3866 — java-1.6.0-sun: Privilege escalation in the Java Web Start Installer (6872824) CVE-2009-3867 — java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303) CVE-2009-3868 — java-1.6.0-sun: Privilege escalation via crafted image file due improper color profiles parsing (6862970) CVE-2009-3869 — OpenJDK JRE AWT setDifflCM stack overflow (6872357) CVE-2009-3871 — OpenJDK JRE AWT setBytePixels heap overflow (6872358) CVE-2009-3872 — JRE JPEG JFIF Decoder issue (6862969) CVE-2009-3873 — OpenJDK JPEG Image Writer quantization problem (6862968) CVE-2009-3874 — OpenJDK ImageI/O JPEG heap overflow (6874643) CVE-2009-3875 — OpenJDK MessageDigest.isEqual introduces timing attack vulnerabilities (6863503) CVE-2009-3876 — OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877 CVE-2009-3877 — OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877

🔗 References (16)