Описание
ELSA-2013-0245: java-1.6.0-openjdk security update (CRITICAL)
[1:1.6.0.0-1.54.1.11.6]
- removed patch8 revertTwoWrongSecurityPatches2013-02-06.patch
- added patch8: 7201064.patch to be reverted
- added patch9: 8005615.patch to fix the 6664509.patch
- Resolves: rhbz#906707
[1:1.6.0.0-1.53.1.11.6]
- added patch8 revertTwoWrongSecurityPatches2013-02-06.patch to remove 6664509 and 7201064 from 1.11.6 tarball
- Resolves: rhbz#906707
[1:1.6.0.0-1.51.1.11.6]
- Updated to icedtea6 1.11.6
- Rewritten java-1.6.0-openjdk-java-access-bridge-security.patch
- Resolves: rhbz#906707
Обновленные пакеты
Oracle Linux 6
Oracle Linux x86_64
java-1.6.0-openjdk
1.6.0.0-1.54.1.11.6.el6_3
java-1.6.0-openjdk-demo
1.6.0.0-1.54.1.11.6.el6_3
java-1.6.0-openjdk-devel
1.6.0.0-1.54.1.11.6.el6_3
java-1.6.0-openjdk-javadoc
1.6.0.0-1.54.1.11.6.el6_3
java-1.6.0-openjdk-src
1.6.0.0-1.54.1.11.6.el6_3
Oracle Linux i686
java-1.6.0-openjdk
1.6.0.0-1.54.1.11.6.el6_3
java-1.6.0-openjdk-demo
1.6.0.0-1.54.1.11.6.el6_3
java-1.6.0-openjdk-devel
1.6.0.0-1.54.1.11.6.el6_3
java-1.6.0-openjdk-javadoc
1.6.0.0-1.54.1.11.6.el6_3
java-1.6.0-openjdk-src
1.6.0.0-1.54.1.11.6.el6_3
Ссылки на источники
Связанные уязвимости
ELSA-2013-0246: java-1.6.0-openjdk security update (IMPORTANT)
ELSA-2013-0247: java-1.7.0-openjdk security update (IMPORTANT)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0428 and CVE-2013-0426. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow remote attackers to bypass Java sandbox restrictions.
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0428 and CVE-2013-0426. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow remote attackers to bypass Java sandbox restrictions.
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0428 and CVE-2013-0426. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow remote attackers to bypass Java sandbox restrictions.