[SUSE-Announcements] BES Auto Notification: New Fixlets Published in Fixlet Site: 'Patches for SUSE Linux Enterprise'

Notification of New SUSE Fixlet Messages suse-announcements at bigmail.bigfix.com
Fri Jan 15 03:10:58 PST 2010


Fixlet Site - 'Patches for SUSE Linux Enterprise'
Current Version: 293	Published: Fri, 15 Jan 2010 01:56:21  GMT

New Fixlets:
============

***************************************************************
Title: PATCH-12565 - Security update for IBM Java2 JRE and SDK - SLES9
Severity: <Unspecified>
Fixlet ID: 1256501
Fixlet Link: http://download.novell.com/Download?buildid=RAXdECFld_U~

Fixlet Description: IBM Java 1.4.2 was updated to 13 fp3. The following security issues were fixed:   CVE-2009-3867: A buffer overflow vulnerability in the Java Runtime Environment audio system might allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet might grant itself permissions to read and write local files, or run local applications that are accessible to the user running the untrusted applet. CVE-2009-3875: A security vulnerability in the Java Runtime Environment with verifying HMAC digests might allow authentication to be bypassed. This action can allow a user to forge a digital signature that would be accepted as valid. Applications that validate HMAC-based digital signatures might be vulnerable to this type of attack. CVE-2009-3869: A buffer overflow vulnerability in the Java Runtime Environment with processing image files might allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet might grant itself permissions to read and write local files or run local applications that are accessible to the user running the untrusted applet. CVE-2009-3871: A buffer overflow vulnerability in the Java Runtime Environment with processing image files might allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet might grant itself permissions to read and write local files or run local applications that are accessible to the user running the untrusted applet. CVE-2009-3874: An integer overflow vulnerability in the Java Runtime Environment with processing JPEG images might allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet might grant itself permissions to read and write local files or run local applications that are accessible to the user running the untrusted applet. Please install the update. Please see patch page for more detailed information.

***************************************************************
Title: PATCH-B10011101 - Security update for IBM Java 1.5.0 - SLES10 SP2
Severity: <Unspecified>
Fixlet ID: 1001110101
Fixlet Link: http://download.novell.com/Download?buildid=OhzcUXz5n-E~

Fixlet Description: A security update for IBM Java 1.5.0  is now available. Everyone using IBM Java 1.5.0 should install this update. Please see patch page for more detailed information.

***************************************************************
Title: PATCH-B10011101 - Security update for IBM Java 1.5.0 - SLED10 SP2
Severity: <Unspecified>
Fixlet ID: 1001110103
Fixlet Link: http://download.novell.com/Download?buildid=-OlUGmHtIKs~

Fixlet Description: A security update for IBM Java 1.5.0  is now available. Everyone using IBM Java 1.5.0 should install this update. Please see patch page for more detailed information.

***************************************************************
Title: PATCH-B10011102 - Security update for flash-player - SLED10 SP2
Severity: <Unspecified>
Fixlet ID: 1001110201
Fixlet Link: http://download.novell.com/Download?buildid=9XwkT0A8u9A~

Fixlet Description: Specially crafted Flash (SWF) files can cause overflows in flash-player. Attackers could potentially exploit that to execute arbitrary code (CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798,CVE-2009-3799, CVE-2009-3800, CVE-2009-3951) Everyone should update. Please see patch page for more detailed information.

***************************************************************
Title: PATCH-B10011103 - Security update for flash-player - SLED10 SP3
Severity: <Unspecified>
Fixlet ID: 1001110301
Fixlet Link: http://download.novell.com/Download?buildid=Tu__ToS159I~

Fixlet Description: Specially crafted Flash (SWF) files can cause overflows in flash-player. Attackers could potentially exploit that to execute arbitrary code (CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798,CVE-2009-3799, CVE-2009-3800, CVE-2009-3951) Everyone should update. Please see patch page for more detailed information.

***************************************************************
Title: PATCH-B10011105 - Security update for IBM Java 1.4.2 - SLES10 SP3
Severity: <Unspecified>
Fixlet ID: 1001110501
Fixlet Link: http://download.novell.com/Download?buildid=aH-NUF9TXVM~

Fixlet Description: IBM Java 1.4.2 was updated to 13 fp3. The following security issues were fixed:     CVE-2009-3867: A buffer overflow vulnerability in the Java Runtime Environment audio system might allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet might grant itself permissions to read and write local files, or run local applications that are accessible to the user running the untrusted applet.   CVE-2009-3875: A security vulnerability in the Java Runtime Environment with verifying HMAC digests might allow authentication to be bypassed. This action can allow a user to forge a digital signature that would be accepted as valid. Applications that validate HMAC-based digital signatures might be vulnerable to this type of attack.   CVE-2009-3869: A buffer overflow vulnerability in the Java Runtime Environment with processing image files might allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet might grant itself permissions to read and write local files or run local applications that are accessible to the user running the untrusted applet.   CVE-2009-3871: A buffer overflow vulnerability in the Java Runtime Environment with processing image files might allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet might grant itself permissions to read and write local files or run local applications that are accessible to the user running the untrusted applet.   CVE-2009-3874: An integer overflow vulnerability in the Java Runtime Environment with processing JPEG images might allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet might grant itself permissions to read and write local files or run local applications that are accessible to the user running the untrusted applet. Please install this update. Please see patch page for more detailed information.

***************************************************************
Title: PATCH-B10011105 - Dependency Conflict - SLES10 SP3
Severity: <Unspecified>
Fixlet ID: 1001110502
Fixlet Link: http://download.novell.com/Download?buildid=aH-NUF9TXVM~

Fixlet Description: Updated java-ibm packages that addresses a security vulnerability are now available. However, the listed computers have the package "java-1_4_2-ibm-plugin" installed, less than version "1.4.2_sr13.3-1.4.1" which conflicts with this security update. You must uninstall or upgrade this package in order for this security update to become relevant.



More information about the SUSE-Announcements mailing list