[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2013-0165 -- Oracle java-1.7.0-openjdk

ID: oval:org.secpod.oval:def:1500065Date: (C)2013-03-20   (M)2023-12-07
Class: PATCHFamily: unix




Updated java-1.7.0-openjdk packages that fix two security issues are nowavailable for Red Hat Enterprise Linux 5 and 6.The Red Hat Security Response Team has rated this update as havingimportant security impact. Common Vulnerability Scoring System basescores, which give detailed severity ratings, are available for eachvulnerability from the CVE links in the References section. These packages provide the OpenJDK 7 Java Runtime Environment and theOpenJDK 7 Software Development Kit.Two improper permission check issues were discovered in the reflection APIin OpenJDK. An untrusted Java application or applet could use these flawsto bypass Java sandbox restrictions. This erratum also upgrades the OpenJDK package to IcedTea7 2.3.4. Refer tothe NEWS file, linked to in the References, for further information.All users of java-1.7.0-openjdk are advised to upgrade to these updatedpackages, which resolve these issues. All running instances of OpenJDK Javamust be restarted for the update to take effect.

Platform:
Oracle Linux 6
Product:
java-1.7.0-openjdk
Reference:
ELSA-2013-0165
CVE-2012-3174
CVE-2013-0422
CVE    2
CVE-2012-3174
CVE-2013-0422
CPE    2
cpe:/a:oracle:java-1.7.0-openjdk
cpe:/o:oracle:linux:6

© SecPod Technologies