RHEL 5 / 6:Satellite Server 中的 IBM Java Runtime (RHSA-2013:1793)

critical Nessus 插件 ID 78984

简介

远程 Red Hat 主机缺少一个或多个安全更新。

描述

更新后的 java-1.6.0-ibm 程序包修复了多个安全问题,现在可用于 Red Hat Network Satellite Server 5.4、5.5 和 5.6。

Red Hat 安全响应团队将此更新评级为具有低危安全影响。可从“参考”部分中的 CVE 链接获取针对每个漏洞的通用漏洞评分系统 (CVSS) 基本分数,其给出了详细的严重性等级。

此更新修正 Red Hat Network Satellite Server 5.4、5.5 和 5.6 随附的 IBM Java Runtime Environment 中的多个安全漏洞。在典型的操作环境中,这些问题的安全风险较低,因为不受信任的小程序上不会使用运行时。

修复了 IBM Java 2 Runtime Environment 中的多个缺陷。
(CVE-2013-3829、CVE-2013-4041、CVE-2013-5372、CVE-2013-5375、CVE-2013-5457、CVE-2013-5772、CVE-2013-5774、CVE-2013-5776、CVE-2013-5778、CVE-2013-5780、CVE-2013-5782、CVE-2013-5783、CVE-2013-5784、CVE-2013-5787、CVE-2013-5789、CVE-2013-5797、CVE-2013-5801、CVE-2013-5802、CVE-2013-5803、CVE-2013-5804、CVE-2013-5809、CVE-2013-5812、CVE-2013-5814、CVE-2013-5817、CVE-2013-5818、CVE-2013-5819、CVE-2013-5820、CVE-2013-5823、CVE-2013-5824、CVE-2013-5825、CVE-2013-5829、CVE-2013-5830、CVE-2013-5831、CVE-2013-5832、CVE-2013-5840、CVE-2013-5842、CVE-2013-5843、CVE-2013-5848、CVE-2013-5849、CVE-2013-5850、CVE-2013-5851)

建议 Red Hat Network Satellite Server 5.4、5.5 和 5.6 的用户升级这些更新后的程序包,其中包含 IBM Java SE 6 SR15 版本。为使此更新生效,必须重新启动 Red Hat Network Satellite Server(“/usr/sbin/rhn-satellite restart”) 以及所有正在运行的 IBM Java 实例。

解决方案

更新受影响的 java-1.6.0-ibm 和/或 java-1.6.0-ibm-devel 程序包。

另见

https://developer.ibm.com/javasdk/support/security-vulnerabilities/

https://access.redhat.com/errata/RHSA-2013:1793

https://access.redhat.com/security/cve/cve-2013-5812

https://access.redhat.com/security/cve/cve-2013-5814

https://access.redhat.com/security/cve/cve-2013-5817

https://access.redhat.com/security/cve/cve-2013-5819

https://access.redhat.com/security/cve/cve-2013-5797

https://access.redhat.com/security/cve/cve-2013-5851

https://access.redhat.com/security/cve/cve-2013-5850

https://access.redhat.com/security/cve/cve-2013-3829

https://access.redhat.com/security/cve/cve-2013-5843

https://access.redhat.com/security/cve/cve-2013-5848

https://access.redhat.com/security/cve/cve-2013-5829

https://access.redhat.com/security/cve/cve-2013-5818

https://access.redhat.com/security/cve/cve-2013-5820

https://access.redhat.com/security/cve/cve-2013-5823

https://access.redhat.com/security/cve/cve-2013-5824

https://access.redhat.com/security/cve/cve-2013-5825

https://access.redhat.com/security/cve/cve-2013-5802

https://access.redhat.com/security/cve/cve-2013-5803

https://access.redhat.com/security/cve/cve-2013-5801

https://access.redhat.com/security/cve/cve-2013-5789

https://access.redhat.com/security/cve/cve-2013-5804

https://access.redhat.com/security/cve/cve-2013-5849

https://access.redhat.com/security/cve/cve-2013-5784

https://access.redhat.com/security/cve/cve-2013-5787

https://access.redhat.com/security/cve/cve-2013-5809

https://access.redhat.com/security/cve/cve-2013-5842

https://access.redhat.com/security/cve/cve-2013-5780

https://access.redhat.com/security/cve/cve-2013-5783

https://access.redhat.com/security/cve/cve-2013-5782

https://access.redhat.com/security/cve/cve-2013-5840

https://access.redhat.com/security/cve/cve-2013-5772

https://access.redhat.com/security/cve/cve-2013-5774

https://access.redhat.com/security/cve/cve-2013-5776

https://access.redhat.com/security/cve/cve-2013-5778

https://access.redhat.com/security/cve/cve-2013-5832

https://access.redhat.com/security/cve/cve-2013-5831

https://access.redhat.com/security/cve/cve-2013-5830

https://access.redhat.com/security/cve/cve-2013-5375

https://access.redhat.com/security/cve/cve-2013-5372

https://access.redhat.com/security/cve/cve-2013-4041

https://access.redhat.com/security/cve/cve-2013-5457

插件详情

严重性: Critical

ID: 78984

文件名: redhat-RHSA-2013-1793.nasl

版本: 1.14

类型: local

代理: unix

发布时间: 2014/11/8

最近更新时间: 2021/1/14

支持的传感器: Agentless Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

风险信息

VPR

风险因素: Medium

分数: 6.5

CVSS v2

风险因素: Critical

基本分数: 10

时间分数: 7.4

矢量: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

漏洞信息

CPE: p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-ibm-devel, cpe:/o:redhat:enterprise_linux:5, cpe:/o:redhat:enterprise_linux:6

必需的 KB 项: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

易利用性: No known exploits are available

补丁发布日期: 2013/12/5

漏洞发布日期: 2013/10/16

参考资料信息

CVE: CVE-2013-3829, CVE-2013-4041, CVE-2013-5372, CVE-2013-5375, CVE-2013-5457, CVE-2013-5772, CVE-2013-5774, CVE-2013-5776, CVE-2013-5778, CVE-2013-5780, CVE-2013-5782, CVE-2013-5783, CVE-2013-5784, CVE-2013-5787, CVE-2013-5789, CVE-2013-5797, CVE-2013-5801, CVE-2013-5802, CVE-2013-5803, CVE-2013-5804, CVE-2013-5809, CVE-2013-5812, CVE-2013-5814, CVE-2013-5817, CVE-2013-5818, CVE-2013-5819, CVE-2013-5820, CVE-2013-5823, CVE-2013-5824, CVE-2013-5825, CVE-2013-5829, CVE-2013-5830, CVE-2013-5831, CVE-2013-5832, CVE-2013-5840, CVE-2013-5842, CVE-2013-5843, CVE-2013-5848, CVE-2013-5849, CVE-2013-5850, CVE-2013-5851

RHSA: 2013:1793