RHEL 6 : java-1.6.0-ibm (RHSA-2011:0357)

critical Nessus Plugin ID 52701

Synopsis

The remote Red Hat host is missing one or more security updates for java-1.6.0-ibm.

Description

The remote Redhat Enterprise Linux 6 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2011:0357 advisory.

The IBM 1.6.0 Java release includes the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit. Detailed vulnerability descriptions are linked from the IBM Security alerts page, listed in the References section. (CVE-2010-4422, CVE-2010-4447, CVE-2010-4448, CVE-2010-4452, CVE-2010-4454, CVE-2010-4462, CVE-2010-4463, CVE-2010-4465, CVE-2010-4466, CVE-2010-4467, CVE-2010-4468, CVE-2010-4471, CVE-2010-4473, CVE-2010-4475)

Note: The RHSA-2010:0987 and RHSA-2011:0290 java-1.6.0-ibm errata were missing 64-bit PowerPC packages for Red Hat Enterprise Linux 4 Extras. This erratum provides 64-bit PowerPC packages for Red Hat Enterprise Linux 4 Extras as expected.

All users of java-1.6.0-ibm are advised to upgrade to these updated packages, containing the IBM 1.6.0 SR9-FP1 Java release. All running instances of IBM Java must be restarted for the update to take effect.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL java-1.6.0-ibm package based on the guidance in RHSA-2011:0357.

See Also

http://www.ibm.com/developerworks/java/jdk/alerts/

http://www.nessus.org/u?9b71d3e7

https://access.redhat.com/security/updates/classification/#critical

https://bugzilla.redhat.com/show_bug.cgi?id=675984

https://bugzilla.redhat.com/show_bug.cgi?id=676019

https://bugzilla.redhat.com/show_bug.cgi?id=676023

https://bugzilla.redhat.com/show_bug.cgi?id=677957

https://bugzilla.redhat.com/show_bug.cgi?id=677958

https://bugzilla.redhat.com/show_bug.cgi?id=677959

https://bugzilla.redhat.com/show_bug.cgi?id=677960

https://bugzilla.redhat.com/show_bug.cgi?id=677961

https://bugzilla.redhat.com/show_bug.cgi?id=677963

https://bugzilla.redhat.com/show_bug.cgi?id=677966

https://bugzilla.redhat.com/show_bug.cgi?id=677967

https://bugzilla.redhat.com/show_bug.cgi?id=677968

https://bugzilla.redhat.com/show_bug.cgi?id=677970

https://bugzilla.redhat.com/show_bug.cgi?id=677971

https://rhn.redhat.com/errata/RHSA-2010-0987.html

https://rhn.redhat.com/errata/RHSA-2011-0290.html

https://access.redhat.com/errata/RHSA-2011:0357

Plugin Details

Severity: Critical

ID: 52701

File Name: redhat-RHSA-2011-0357.nasl

Version: 1.35

Type: local

Agent: unix

Published: 3/17/2011

Updated: 4/14/2025

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.8

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2010-4473

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-accessibility, cpe:/o:redhat:enterprise_linux:5, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-src, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-javacomm, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-plugin, cpe:/o:redhat:enterprise_linux:6, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-demo, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-devel, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-jdbc

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/16/2011

Vulnerability Publication Date: 2/17/2011

Exploitable With

CANVAS (CANVAS)

Core Impact

Metasploit (Sun Java Applet2ClassLoader Remote Code Execution)

Reference Information

CVE: CVE-2010-4422, CVE-2010-4447, CVE-2010-4448, CVE-2010-4452, CVE-2010-4454, CVE-2010-4462, CVE-2010-4463, CVE-2010-4465, CVE-2010-4466, CVE-2010-4467, CVE-2010-4468, CVE-2010-4471, CVE-2010-4473, CVE-2010-4475

BID: 46386, 46388, 46391, 46393, 46394, 46395, 46398, 46399, 46402, 46403, 46406, 46409, 46410, 46411

RHSA: 2011:0357