Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: [UPDATE] Sun Java: Multiple
Posted by Benjamin D. Thomas
Multiple vulnerabilities have been reported in Sun Java, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a user's system. [UPDATE] The issue is fixed in Pardus 2008
------------------------------------------------------------------------
Pardus Linux Security Advisory 2010-22 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2010-02-04
Severity: 4
Type: Local
------------------------------------------------------------------------
Summary
=======
Multiple vulnerabilities have been reported in Sun Java, which can be
exploited by malicious people to disclose sensitive information, bypass
certain security restrictions, cause a DoS (Denial of Service), or
compromise a user's system. [UPDATE] The issue is fixed in Pardus 2008
Description
===========
New version of Sun Java fixes several vulnerabilities in the Sun Java 6
Runtime Environment and the Sun Java 6 Software Development Kit. These
vulnerabilities are summarized on the "Advance notification of Security
Updates for Java SE" page from Sun Microsystems, listed in the
References section. (CVE-2009-2409, CVE-2009-3728, CVE-2009-3729,
CVE-2009-3865, CVE-2009-3866, CVE-2009-3867, CVE-2009-3868,
CVE-2009-3869, CVE-2009-3871,CVE-2009-3872, CVE-2009-3873,
CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, CVE-2009-3877,
CVE-2009-3879, CVE-2009-3880, CVE-2009-3881, CVE-2009-3882,
CVE-2009-3883, CVE-2009-3884, CVE-2009-3886)
Affected packages:
Pardus 2009:
sun-jdk, all before 1.6.0_p17-21-5
sun-jre, all before 1.6.0_p17-21-5
Pardus 2008:
sun-jdk, all before 1.6.0_p17-20-7
sun-jre, all before 1.6.0_p17-20-7
Resolution
==========
There are update(s) for sun-jdk, sun-jre. You can update them via
Package Manager or with a single command from console:
Pardus 2008:
pisi up sun-jdk sun-jre
Pardus 2009:
pisi up sun-jdk sun-jre
References
==========
* http://bugs.pardus.org.tr/show_bug.cgi?id=11946
* http://java.sun.com/javase/6/webnotes/6u17.html