RHEL 5 / 6 : java-1.7.0-oracle (RHSA-2014:0030)

medium Nessus Plugin ID 71987

Synopsis

The remote Red Hat host is missing one or more security updates for java-1.7.0-oracle.

Description

The remote Redhat Enterprise Linux 5 / 6 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2014:0030 advisory.

Oracle Java SE version 7 includes the Oracle Java Runtime Environment and the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime Environment and the Oracle Java Software Development Kit. Further information about these flaws can be found on the Oracle Java SE Critical Patch Update Advisory page, listed in the References section.
(CVE-2013-5870, CVE-2013-5878, CVE-2013-5884, CVE-2013-5887, CVE-2013-5888, CVE-2013-5889, CVE-2013-5893, CVE-2013-5895, CVE-2013-5896, CVE-2013-5898, CVE-2013-5899, CVE-2013-5902, CVE-2013-5904, CVE-2013-5905, CVE-2013-5906, CVE-2013-5907, CVE-2013-5910, CVE-2014-0368, CVE-2014-0373, CVE-2014-0375, CVE-2014-0376, CVE-2014-0382, CVE-2014-0387, CVE-2014-0403, CVE-2014-0410, CVE-2014-0411, CVE-2014-0415, CVE-2014-0416, CVE-2014-0417, CVE-2014-0418, CVE-2014-0422, CVE-2014-0423, CVE-2014-0424, CVE-2014-0428)

All users of java-1.7.0-oracle are advised to upgrade to these updated packages, which provide Oracle Java 7 Update 51 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to take effect.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL java-1.7.0-oracle package based on the guidance in RHSA-2014:0030.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=1052915

https://bugzilla.redhat.com/show_bug.cgi?id=1052919

https://bugzilla.redhat.com/show_bug.cgi?id=1052942

https://bugzilla.redhat.com/show_bug.cgi?id=1053010

https://bugzilla.redhat.com/show_bug.cgi?id=1053066

https://bugzilla.redhat.com/show_bug.cgi?id=1053266

https://bugzilla.redhat.com/show_bug.cgi?id=1053495

https://bugzilla.redhat.com/show_bug.cgi?id=1053496

https://bugzilla.redhat.com/show_bug.cgi?id=1053499

https://bugzilla.redhat.com/show_bug.cgi?id=1053501

https://bugzilla.redhat.com/show_bug.cgi?id=1053502

https://bugzilla.redhat.com/show_bug.cgi?id=1053504

https://bugzilla.redhat.com/show_bug.cgi?id=1053506

https://bugzilla.redhat.com/show_bug.cgi?id=1053507

https://bugzilla.redhat.com/show_bug.cgi?id=1053508

https://bugzilla.redhat.com/show_bug.cgi?id=1053509

https://bugzilla.redhat.com/show_bug.cgi?id=1053510

https://bugzilla.redhat.com/show_bug.cgi?id=1053512

https://bugzilla.redhat.com/show_bug.cgi?id=1053513

https://bugzilla.redhat.com/show_bug.cgi?id=1053515

https://bugzilla.redhat.com/show_bug.cgi?id=1053516

https://bugzilla.redhat.com/show_bug.cgi?id=1053517

https://bugzilla.redhat.com/show_bug.cgi?id=1053518

https://bugzilla.redhat.com/show_bug.cgi?id=1053540

http://www.nessus.org/u?17c46362

http://www.nessus.org/u?b9251a9b

https://access.redhat.com/errata/RHSA-2014:0030

https://access.redhat.com/security/updates/classification/#critical

https://bugzilla.redhat.com/show_bug.cgi?id=1051519

https://bugzilla.redhat.com/show_bug.cgi?id=1051528

https://bugzilla.redhat.com/show_bug.cgi?id=1051549

https://bugzilla.redhat.com/show_bug.cgi?id=1051699

https://bugzilla.redhat.com/show_bug.cgi?id=1051823

https://bugzilla.redhat.com/show_bug.cgi?id=1051911

https://bugzilla.redhat.com/show_bug.cgi?id=1051912

https://bugzilla.redhat.com/show_bug.cgi?id=1051923

Plugin Details

Severity: Medium

ID: 71987

File Name: redhat-RHSA-2014-0030.nasl

Version: 1.20

Type: local

Agent: unix

Published: 1/16/2014

Updated: 3/20/2025

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.5

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2014-0428

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2013-4578

Vulnerability Information

CPE: cpe:/o:redhat:enterprise_linux:5, p-cpe:/a:redhat:enterprise_linux:java-1.7.0-oracle, p-cpe:/a:redhat:enterprise_linux:java-1.7.0-oracle-jdbc, p-cpe:/a:redhat:enterprise_linux:java-1.7.0-oracle-src, cpe:/o:redhat:enterprise_linux:6, p-cpe:/a:redhat:enterprise_linux:java-1.7.0-oracle-devel, p-cpe:/a:redhat:enterprise_linux:java-1.7.0-oracle-plugin, p-cpe:/a:redhat:enterprise_linux:java-1.7.0-oracle-javafx

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 1/15/2014

Reference Information

CVE: CVE-2013-4578, CVE-2013-5870, CVE-2013-5878, CVE-2013-5884, CVE-2013-5887, CVE-2013-5888, CVE-2013-5889, CVE-2013-5893, CVE-2013-5895, CVE-2013-5896, CVE-2013-5898, CVE-2013-5899, CVE-2013-5902, CVE-2013-5904, CVE-2013-5905, CVE-2013-5906, CVE-2013-5907, CVE-2013-5910, CVE-2014-0368, CVE-2014-0373, CVE-2014-0375, CVE-2014-0376, CVE-2014-0382, CVE-2014-0387, CVE-2014-0403, CVE-2014-0410, CVE-2014-0411, CVE-2014-0415, CVE-2014-0416, CVE-2014-0417, CVE-2014-0418, CVE-2014-0422, CVE-2014-0423, CVE-2014-0424, CVE-2014-0428

BID: 64863, 64875, 64882, 64890, 64894, 64899, 64903, 64906, 64907, 64912, 64914, 64915, 64916, 64917, 64918, 64919, 64920, 64921, 64922, 64923, 64924, 64925, 64926, 64927, 64928, 64929, 64930, 64931, 64932, 64933, 64934, 64935, 64936, 64937

RHSA: 2014:0030