-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: java-1.7.1-ibm security update
Advisory ID:       RHSA-2018:2576-01
Product:           Red Hat Enterprise Linux Supplementary
Advisory URL:      https://access.redhat.com/errata/RHSA-2018:2576
Issue date:        2018-08-28
CVE Names:         CVE-2018-1517 CVE-2018-1656 CVE-2018-2940 
                   CVE-2018-2952 CVE-2018-2973 CVE-2018-12539 
====================================================================
1. Summary:

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux
6 Supplementary.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64
Red Hat Enterprise Linux HPC Node Supplementary (v. 6) - x86_64
Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, ppc64, s390x, x86_64
Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64

3. Description:

IBM Java SE version 7 Release 1 includes the IBM Java Runtime Environment
and the IBM Java Software Development Kit.

This update upgrades IBM Java SE 7 to version 7R1 SR4-FP30.

Security Fix(es):

* IBM JDK: privilege escalation via insufficiently restricted access to
Attach API (CVE-2018-12539)

* IBM JDK: DoS in the java.math component (CVE-2018-1517)

* IBM JDK: path traversal flaw in the Diagnostic Tooling Framework
(CVE-2018-1656)

* Oracle JDK: unspecified vulnerability fixed in 6u201, 7u191, 8u181, and
10.0.2 (Libraries) (CVE-2018-2940)

* OpenJDK: insufficient index validation in PatternSyntaxException
getMessage() (Concurrency, 8199547) (CVE-2018-2952)

* Oracle JDK: unspecified vulnerability fixed in 6u201, 7u191, 8u181, and
10.0.2 (JSSE) (CVE-2018-2973)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

All running instances of IBM Java must be restarted for this update to take
effect.

5. Bugs fixed (https://bugzilla.redhat.com/):

1600925 - CVE-2018-2952 OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547)
1602145 - CVE-2018-2973 Oracle JDK: unspecified vulnerability fixed in 6u201, 7u191, 8u181, and 10.0.2 (JSSE)
1602146 - CVE-2018-2940 Oracle JDK: unspecified vulnerability fixed in 6u201, 7u191, 8u181, and 10.0.2 (Libraries)
1618767 - CVE-2018-12539 IBM JDK: privilege escalation via insufficiently restricted access to Attach API
1618869 - CVE-2018-1656 IBM JDK: path traversal flaw in the Diagnostic Tooling Framework
1618871 - CVE-2018-1517 IBM JDK: DoS in the java.math component

6. Package List:

Red Hat Enterprise Linux Desktop Supplementary (v. 6):

i386:
java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-plugin-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.i686.rpm

x86_64:
java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-plugin-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm

Red Hat Enterprise Linux HPC Node Supplementary (v. 6):

x86_64:
java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm

Red Hat Enterprise Linux Server Supplementary (v. 6):

i386:
java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-plugin-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.i686.rpm

ppc64:
java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.ppc64.rpm
java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.ppc64.rpm
java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.ppc64.rpm
java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.ppc64.rpm
java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.ppc64.rpm

s390x:
java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.s390x.rpm
java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.s390x.rpm
java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.s390x.rpm
java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.s390x.rpm
java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.s390x.rpm

x86_64:
java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-plugin-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm

Red Hat Enterprise Linux Workstation Supplementary (v. 6):

i386:
java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-plugin-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.i686.rpm

x86_64:
java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-plugin-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2018-1517
https://access.redhat.com/security/cve/CVE-2018-1656
https://access.redhat.com/security/cve/CVE-2018-2940
https://access.redhat.com/security/cve/CVE-2018-2952
https://access.redhat.com/security/cve/CVE-2018-2973
https://access.redhat.com/security/cve/CVE-2018-12539
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2018 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBW4WgpNzjgjWX9erEAQhubg//eQSeYLgVmNMMSAWL47e0E2cF8eWuIJPs
kuHw64k42v4B27+Jha/qCcbjxMBcIPndLXvDbDPobSn4saobh+UyWLnVrjQZFnxO
oE+hKy0LVraHtSldSX7VvvdU9SYeIKpYSKbK7KwWifJ91tNlXE/TFZFuC0FWlTSw
FvMpk/0YxfoZ+4tBJqS4DGTMcZd4M+3bAOfLb8Yacm0x9Pd2zw9c9Dxp2eZIwCzf
8U0c7HfjfdL99KJdD0UxrRsJO7V5bQNhNrXArwVHpWoB8PdJDGCdZ32yeiuwTdaz
LR29kWdgKgKgvzj8H0Vhth5GWrjPHKsz7rzI22mFvElsZRJFnGwACliIA649taoa
D6Qo5SyDWXDVK29r8A9yWS73Qhq67tF7YS1x+N/AjGI/XIB/QK/T5RMfjeP8CMYx
/eql7vU3WezXZK87oQhuOiyuPyZvWaKFKiECwcJIcQyikVGXtBWKrYi3VnkH4y66
C6AadmE7Sl9DXSkyXEnbTJfeovv4ZLTTWWTES+hs+YdFFs9VGn8UUeePmDPk/l3g
E/RosCFHnq/3oxV+ZozH+vee2x09GTiJhsWmSJVrOMAc8xFyjGlvjholAoKTjx0G
HdQlcOcu/42QQ93IDMJLVCHSe3IiCrNheTShE4vU9dwsqdKJ7djmZdVTKQMrxNua
lsZnQnZC2Lw=vWp5
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2018-2576:01 Important: java-1.7.1-ibm security update

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary

Summary

IBM Java SE version 7 Release 1 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit.
This update upgrades IBM Java SE 7 to version 7R1 SR4-FP30.
Security Fix(es):
* IBM JDK: privilege escalation via insufficiently restricted access to Attach API (CVE-2018-12539)
* IBM JDK: DoS in the java.math component (CVE-2018-1517)
* IBM JDK: path traversal flaw in the Diagnostic Tooling Framework (CVE-2018-1656)
* Oracle JDK: unspecified vulnerability fixed in 6u201, 7u191, 8u181, and 10.0.2 (Libraries) (CVE-2018-2940)
* OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) (CVE-2018-2952)
* Oracle JDK: unspecified vulnerability fixed in 6u201, 7u191, 8u181, and 10.0.2 (JSSE) (CVE-2018-2973)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
All running instances of IBM Java must be restarted for this update to take effect.

References

https://access.redhat.com/security/cve/CVE-2018-1517 https://access.redhat.com/security/cve/CVE-2018-1656 https://access.redhat.com/security/cve/CVE-2018-2940 https://access.redhat.com/security/cve/CVE-2018-2952 https://access.redhat.com/security/cve/CVE-2018-2973 https://access.redhat.com/security/cve/CVE-2018-12539 https://access.redhat.com/security/updates/classification/#important

Package List

Red Hat Enterprise Linux Desktop Supplementary (v. 6):
i386: java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-plugin-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
x86_64: java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-plugin-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
Red Hat Enterprise Linux HPC Node Supplementary (v. 6):
x86_64: java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
Red Hat Enterprise Linux Server Supplementary (v. 6):
i386: java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-plugin-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
ppc64: java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.ppc64.rpm java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.ppc64.rpm java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.ppc64.rpm java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.ppc64.rpm java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.ppc64.rpm
s390x: java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.s390x.rpm java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.s390x.rpm java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.s390x.rpm java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.s390x.rpm java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.s390x.rpm
x86_64: java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-plugin-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
Red Hat Enterprise Linux Workstation Supplementary (v. 6):
i386: java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-plugin-1.7.1.4.30-1jpp.2.el6_10.i686.rpm java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.i686.rpm
x86_64: java-1.7.1-ibm-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-demo-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-devel-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-jdbc-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-plugin-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm java-1.7.1-ibm-src-1.7.1.4.30-1jpp.2.el6_10.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2018:2576-01
Product: Red Hat Enterprise Linux Supplementary
Advisory URL: https://access.redhat.com/errata/RHSA-2018:2576
Issued Date: : 2018-08-28
CVE Names: CVE-2018-1517 CVE-2018-1656 CVE-2018-2940 CVE-2018-2952 CVE-2018-2973 CVE-2018-12539

Topic

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux6 Supplementary.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64

Red Hat Enterprise Linux HPC Node Supplementary (v. 6) - x86_64

Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, ppc64, s390x, x86_64

Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64


Bugs Fixed

1600925 - CVE-2018-2952 OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547)

1602145 - CVE-2018-2973 Oracle JDK: unspecified vulnerability fixed in 6u201, 7u191, 8u181, and 10.0.2 (JSSE)

1602146 - CVE-2018-2940 Oracle JDK: unspecified vulnerability fixed in 6u201, 7u191, 8u181, and 10.0.2 (Libraries)

1618767 - CVE-2018-12539 IBM JDK: privilege escalation via insufficiently restricted access to Attach API

1618869 - CVE-2018-1656 IBM JDK: path traversal flaw in the Diagnostic Tooling Framework

1618871 - CVE-2018-1517 IBM JDK: DoS in the java.math component


Related News