First published: Thu Dec 04 2008(Updated: )
The Java Runtime Environment (JRE) contains the software and tools that<br>users need to run applets and applications written using the Java<br>programming language. <br>A vulnerability was found in in Java Web Start. If a user visits a<br>malicious website, an attacker could misuse this flaw to execute arbitrary<br>code. (CVE-2008-2086)<br>Additionally, these packages fix several other vulnerabilities. These are<br>summarized in the "Advance notification of Security Updates for Java SE"<br>from Sun Microsystems. <br>Users of java-1.5.0-sun should upgrade to these updated packages, which<br>correct these issues.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2008:1025 is classified as critical due to the potential for remote code execution.
To fix RHSA-2008:1025, users should update their Java Runtime Environment to the latest version provided by Red Hat.
RHSA-2008:1025 affects systems running vulnerable versions of the Java Runtime Environment.
The main vulnerability in RHSA-2008:1025 is a flaw in Java Web Start that can be exploited by visiting malicious websites.
There are no reliable workarounds for RHSA-2008:1025, and it is recommended to apply the fix as soon as possible.