First published: Fri Aug 28 2009(Updated: )
The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment and<br>the IBM Java 2 Software Development Kit.<br>This update fixes several vulnerabilities in the IBM Java 2 Runtime<br>Environment and the IBM Java 2 Software Development Kit. These<br>vulnerabilities are summarized on the IBM "Security alerts" page listed in<br>the References section. (CVE-2009-2625, CVE-2009-2670, CVE-2009-2671,<br>CVE-2009-2672, CVE-2009-2673, CVE-2009-2675)<br>All users of java-1.5.0-ibm are advised to upgrade to these updated<br>packages, containing the IBM 1.5.0 SR10 Java release. All running instances<br>of IBM Java must be restarted for this update to take effect.<br>Note: The packages included in this update are identical to the packages<br>made available by RHEA-2009:1208 and RHEA-2009:1210 on the 13th of<br>August 2009. These packages are being reissued as a Red Hat Security<br>Advisory as they fixed a number of security issues that were not made<br>public until after those errata were released. Since the packages are<br>identical, there is no need to install this update if RHEA-2009:1208 or<br>RHEA-2009:1210 has already been installed.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.5.0-ibm-1.5.0.10-1jpp.4.el5 | 1.5.0-ibm-1.5.0.10-1jpp.4.el5 |
redhat/java | <1.5.0-ibm-1.5.0.10-1jpp.4.el5 | 1.5.0-ibm-1.5.0.10-1jpp.4.el5 |
redhat/java | <1.5.0-ibm-accessibility-1.5.0.10-1jpp.4.el5 | 1.5.0-ibm-accessibility-1.5.0.10-1jpp.4.el5 |
redhat/java | <1.5.0-ibm-demo-1.5.0.10-1jpp.4.el5 | 1.5.0-ibm-demo-1.5.0.10-1jpp.4.el5 |
redhat/java | <1.5.0-ibm-demo-1.5.0.10-1jpp.4.el5 | 1.5.0-ibm-demo-1.5.0.10-1jpp.4.el5 |
redhat/java | <1.5.0-ibm-devel-1.5.0.10-1jpp.4.el5 | 1.5.0-ibm-devel-1.5.0.10-1jpp.4.el5 |
redhat/java | <1.5.0-ibm-devel-1.5.0.10-1jpp.4.el5 | 1.5.0-ibm-devel-1.5.0.10-1jpp.4.el5 |
redhat/java | <1.5.0-ibm-javacomm-1.5.0.10-1jpp.4.el5 | 1.5.0-ibm-javacomm-1.5.0.10-1jpp.4.el5 |
redhat/java | <1.5.0-ibm-javacomm-1.5.0.10-1jpp.4.el5 | 1.5.0-ibm-javacomm-1.5.0.10-1jpp.4.el5 |
redhat/java | <1.5.0-ibm-jdbc-1.5.0.10-1jpp.4.el5 | 1.5.0-ibm-jdbc-1.5.0.10-1jpp.4.el5 |
redhat/java | <1.5.0-ibm-plugin-1.5.0.10-1jpp.4.el5 | 1.5.0-ibm-plugin-1.5.0.10-1jpp.4.el5 |
redhat/java | <1.5.0-ibm-src-1.5.0.10-1jpp.4.el5 | 1.5.0-ibm-src-1.5.0.10-1jpp.4.el5 |
redhat/java | <1.5.0-ibm-src-1.5.0.10-1jpp.4.el5 | 1.5.0-ibm-src-1.5.0.10-1jpp.4.el5 |
redhat/java | <1.5.0-ibm-accessibility-1.5.0.10-1jpp.4.el5 | 1.5.0-ibm-accessibility-1.5.0.10-1jpp.4.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability fixed by RHSA-2009:1236 is considered critical, impacting the security of applications utilizing IBM Java 2 Runtime Environment.
To fix RHSA-2009:1236, users should update to the latest version of IBM Java specified in the advisory, namely 1.5.0-ibm-1.5.0.10-1jpp.4.el5.
RHSA-2009:1236 affects various IBM Java packages, including java, java-accessibility, java-demo, java-devel, java-javacomm, java-jdbc, java-plugin, and java-src.
Yes, RHSA-2009:1236 specifically addresses vulnerabilities in IBM Java version 1.5.0.
If you cannot update your system for RHSA-2009:1236, consider implementing workarounds or additional security measures to mitigate risks associated with the vulnerabilities.