RHSA-2009:0377: Important: java-1.6.0-openjdk security update

Published Apr 7, 2009
·
Updated

These packages provide the OpenJDK 6 Java Runtime Environment and theOpenJDK 6 Software Development Kit. The Java Runtime Environment (JRE)contains the software and tools that users need to run applications writtenusing the Java programming language.A flaw was found in the way that the Java Virtual Machine (JVM) handledtemporary font files. A malicious applet could use this flaw to use largeamounts of disk space, causing a denial of service. (CVE-2006-2426)A memory leak flaw was found in LittleCMS (embedded in OpenJDK). Anapplication using color profiles could use excessive amounts of memory, andpossibly crash after using all available memory, if used to openspecially-crafted images. (CVE-2009-0581)Multiple integer overflow flaws which could lead to heap-based bufferoverflows, as well as multiple insufficient input validation flaws, werefound in the way LittleCMS handled color profiles. An attacker could usethese flaws to create a specially-crafted image file which could cause aJava application to crash or, possibly, execute arbitrary code when opened.(CVE-2009-0723, CVE-2009-0733)A null pointer dereference flaw was found in LittleCMS. An applicationusing color profiles could crash while converting a specially-crafted imagefile. (CVE-2009-0793)A flaw in the Java API for XML Web Services (JAX-WS) service endpointhandling could allow a remote attacker to cause a denial of service on theserver application hosting the JAX-WS service endpoint. (CVE-2009-1101)A flaw in the way the Java Runtime Environment initialized LDAP connectionscould allow a remote, authenticated user to cause a denial of service onthe LDAP service. (CVE-2009-1093)A flaw in the Java Runtime Environment LDAP client could allow maliciousdata from an LDAP server to cause arbitrary code to be loaded and then runon an LDAP client. (CVE-2009-1094)Several buffer overflow flaws were found in the Java Runtime Environmentunpack200 functionality. An untrusted applet could extend its privileges,allowing it to read and write local files, as well as to execute localapplications with the privileges of the user running the applet.(CVE-2009-1095, CVE-2009-1096)A flaw in the Java Runtime Environment Virtual Machine code generationfunctionality could allow untrusted applets to extend their privileges. Anuntrusted applet could extend its privileges, allowing it to read and writelocal files, as well as execute local applications with the privilegesof the user running the applet. (CVE-2009-1102)A buffer overflow flaw was found in the splash screen processing. A remoteattacker could extend privileges to read and write local files, as well asto execute local applications with the privileges of the user running thejava process. (CVE-2009-1097)A buffer overflow flaw was found in how GIF images were processed. A remoteattacker could extend privileges to read and write local files, as well asexecute local applications with the privileges of the user running thejava process. (CVE-2009-1098)Note: The flaws concerning applets in this advisory, CVE-2009-1095,CVE-2009-1096, and CVE-2009-1102, can only be triggered injava-1.6.0-openjdk by calling the "appletviewer" application.All users of java-1.6.0-openjdk are advised to upgrade to these updatedpackages, which resolve these issues. All running instances of OpenJDK Javamust be restarted for the update to take effect.

Affected Software

10 affected componentsFixes available
redhat/java<1.6.0-openjdk-1.6.0.0-0.30.b09.el5
1.6.0-openjdk-1.6.0.0-0.30.b09.el5
redhat/java<1.6.0-openjdk-1.6.0.0-0.30.b09.el5
1.6.0-openjdk-1.6.0.0-0.30.b09.el5
redhat/java<1.6.0-openjdk-demo-1.6.0.0-0.30.b09.el5
1.6.0-openjdk-demo-1.6.0.0-0.30.b09.el5
redhat/java<1.6.0-openjdk-devel-1.6.0.0-0.30.b09.el5
1.6.0-openjdk-devel-1.6.0.0-0.30.b09.el5
redhat/java<1.6.0-openjdk-javadoc-1.6.0.0-0.30.b09.el5
1.6.0-openjdk-javadoc-1.6.0.0-0.30.b09.el5
redhat/java<1.6.0-openjdk-src-1.6.0.0-0.30.b09.el5
1.6.0-openjdk-src-1.6.0.0-0.30.b09.el5
redhat/java<1.6.0-openjdk-demo-1.6.0.0-0.30.b09.el5
1.6.0-openjdk-demo-1.6.0.0-0.30.b09.el5
redhat/java<1.6.0-openjdk-devel-1.6.0.0-0.30.b09.el5
1.6.0-openjdk-devel-1.6.0.0-0.30.b09.el5
redhat/java<1.6.0-openjdk-javadoc-1.6.0.0-0.30.b09.el5
1.6.0-openjdk-javadoc-1.6.0.0-0.30.b09.el5
redhat/java<1.6.0-openjdk-src-1.6.0.0-0.30.b09.el5
1.6.0-openjdk-src-1.6.0.0-0.30.b09.el5

Remediation

Event History

Apr 7, 2009
Advisory Published
via Red Hat·12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2009:0377?

The severity of RHSA-2009:0377 is classified as critical due to a significant vulnerability in the OpenJDK 6 packages.

2

How do I fix RHSA-2009:0377?

To fix RHSA-2009:0377, you should update the affected OpenJDK 6 packages to version 1.6.0-openjdk-1.6.0.0-0.30.b09.el5 or higher.

3

What versions of OpenJDK are affected by RHSA-2009:0377?

RHSA-2009:0377 affects multiple versions of OpenJDK 6, specifically versions prior to 1.6.0-openjdk-1.6.0.0-0.30.b09.el5.

4

What packages are included in RHSA-2009:0377?

RHSA-2009:0377 includes the OpenJDK 6 Java Runtime Environment, Software Development Kit, and associated packages like demo, javadoc, and src.

5

Who issued the advisory for RHSA-2009:0377?

The advisory for RHSA-2009:0377 was issued by Red Hat as part of its security errata.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203