SuSE 10 Security Update : java-1_5_0-ibm (ZYPP Patch Number 8653)

critical Nessus Plugin ID 69093

Synopsis

The remote SuSE 10 host is missing a security-related patch.

Description

IBM Java 1.5.0 has been updated to SR16-FP3 to fix bugs and security issues.

Please see also http://www.ibm.com/developerworks/java/jdk/alerts/

Also the following bug has been fixed :

- add Europe/Busingen to tzmappings. (bnc#817062)

- mark files in jre/bin and bin/ as executable (bnc#823034)

Solution

Apply ZYPP patch number 8653.

See Also

http://support.novell.com/security/cve/CVE-2013-4002.html

http://support.novell.com/security/cve/CVE-2013-1500.html

http://support.novell.com/security/cve/CVE-2013-1571.html

http://support.novell.com/security/cve/CVE-2013-2443.html

http://support.novell.com/security/cve/CVE-2013-2444.html

http://support.novell.com/security/cve/CVE-2013-2446.html

http://support.novell.com/security/cve/CVE-2013-2447.html

http://support.novell.com/security/cve/CVE-2013-2448.html

http://support.novell.com/security/cve/CVE-2013-2450.html

http://support.novell.com/security/cve/CVE-2013-2452.html

http://support.novell.com/security/cve/CVE-2013-2454.html

http://support.novell.com/security/cve/CVE-2013-2455.html

http://support.novell.com/security/cve/CVE-2013-2456.html

http://support.novell.com/security/cve/CVE-2013-2457.html

http://support.novell.com/security/cve/CVE-2013-2459.html

http://support.novell.com/security/cve/CVE-2013-2463.html

http://support.novell.com/security/cve/CVE-2013-2464.html

http://support.novell.com/security/cve/CVE-2013-2465.html

http://support.novell.com/security/cve/CVE-2013-2469.html

http://support.novell.com/security/cve/CVE-2013-2470.html

http://support.novell.com/security/cve/CVE-2013-2471.html

http://support.novell.com/security/cve/CVE-2013-2472.html

http://support.novell.com/security/cve/CVE-2013-2473.html

http://support.novell.com/security/cve/CVE-2013-3009.html

http://support.novell.com/security/cve/CVE-2013-3011.html

http://support.novell.com/security/cve/CVE-2013-3012.html

http://support.novell.com/security/cve/CVE-2013-3743.html

Plugin Details

Severity: Critical

ID: 69093

File Name: suse_java-1_5_0-ibm-8653.nasl

Version: 1.5

Type: local

Agent: unix

Published: 7/28/2013

Updated: 3/29/2022

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.8

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/o:suse:suse_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/23/2013

Vulnerability Publication Date: 6/18/2013

CISA Known Exploited Vulnerability Due Dates: 4/18/2022

Exploitable With

Core Impact

Metasploit (Java storeImageArray() Invalid Array Indexing Vulnerability)

Reference Information

CVE: CVE-2013-1500, CVE-2013-1571, CVE-2013-2443, CVE-2013-2444, CVE-2013-2446, CVE-2013-2447, CVE-2013-2448, CVE-2013-2450, CVE-2013-2452, CVE-2013-2454, CVE-2013-2455, CVE-2013-2456, CVE-2013-2457, CVE-2013-2459, CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, CVE-2013-2472, CVE-2013-2473, CVE-2013-3009, CVE-2013-3011, CVE-2013-3012, CVE-2013-3743, CVE-2013-4002