[SUSE-Announcements] BES Auto Notification: New Fixlets Published in Fixlet Site: 'Patches for SUSE Linux Enterprise'

Notification of New SUSE Fixlet Messages suse-announcements at bigmail.bigfix.com
Wed Jan 13 03:11:51 PST 2010


Fixlet Site - 'Patches for SUSE Linux Enterprise'
Current Version: 292	Published: Tue, 12 Jan 2010 23:55:13  GMT

New Fixlets:
============

***************************************************************
Title: PATCH-B10011104 - Security update for IBM Java 1.4.2 - SLES10 SP2
Severity: <Unspecified>
Fixlet ID: 1001110401
Fixlet Link: http://download.novell.com/Download?buildid=2W0jS0q3Flk~

Fixlet Description: IBM Java 1.4.2 was updated to 13 fp3. The following security issues were fixed:     CVE-2009-3867: A buffer overflow vulnerability in the Java Runtime Environment audio system might allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet might grant itself permissions to read and write local files, or run local applications that are accessible to the user running the untrusted applet.   CVE-2009-3875: A security vulnerability in the Java Runtime Environment with verifying HMAC digests might allow authentication to be bypassed. This action can allow a user to forge a digital signature that would be accepted as valid. Applications that validate HMAC-based digital signatures might be vulnerable to this type of attack.   CVE-2009-3869: A buffer overflow vulnerability in the Java Runtime Environment with processing image files might allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet might grant itself permissions to read and write local files or run local applications that are accessible to the user running the untrusted applet.   CVE-2009-3871: A buffer overflow vulnerability in the Java Runtime Environment with processing image files might allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet might grant itself permissions to read and write local files or run local applications that are accessible to the user running the untrusted applet.   CVE-2009-3874: An integer overflow vulnerability in the Java Runtime Environment with processing JPEG images might allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet might grant itself permissions to read and write local files or run local applications that are accessible to the user running the untrusted applet. Please install this update. Please see patch page for more detailed information.



More information about the SUSE-Announcements mailing list