RHSA-2010:0408Medium
Red Hat Security Advisory: java-1.4.2-ibm security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2009-3555 — TLS: MITM attacks via session renegotiation CVE-2009-3867 — java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303) CVE-2009-3869 — OpenJDK JRE AWT setDifflCM stack overflow (6872357) CVE-2009-3871 — OpenJDK JRE AWT setBytePixels heap overflow (6872358) CVE-2009-3874 — OpenJDK ImageI/O JPEG heap overflow (6874643) CVE-2009-3875 — OpenJDK MessageDigest.isEqual introduces timing attack vulnerabilities (6863503)
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2010:0408
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttp://kbase.redhat.com/faq/docs/DOC-20491
- externalhttp://www.ibm.com/developerworks/java/jdk/alerts/
- externalhttp://www.ibm.com/developerworks/java/jdk/security/142/secguides/jsse2docs/JSSE2RefGuide.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=530057
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=530062
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=530063
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=530067
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=533125
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=533214
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2010/rhsa-2010_0408.json