RHSA-2010:0865: Important: java-1.6.0-openjdk security and bug fix update

Published Nov 10, 2010
·
Updated

These packages provide the OpenJDK 6 Java Runtime Environment and theOpenJDK 6 Software Development Kit.defaultReadObject of the Serialization API could be tricked into setting avolatile field multiple times, which could allow a remote attacker toexecute arbitrary code with the privileges of the user running the appletor application. (CVE-2010-3569)Race condition in the way objects were deserialized could allow anuntrusted applet or application to misuse the privileges of the userrunning the applet or application. (CVE-2010-3568)Miscalculation in the OpenType font rendering implementation causedout-of-bounds memory access, which could allow remote attackers to executecode with the privileges of the user running the java process.(CVE-2010-3567)JPEGImageWriter.writeImage in the imageio API improperly checked certainimage metadata, which could allow a remote attacker to execute arbitrarycode in the context of the user running the applet or application.(CVE-2010-3565)Double free in IndexColorModel could cause an untrusted applet orapplication to crash or, possibly, execute arbitrary code with theprivileges of the user running the applet or application. (CVE-2010-3562)The privileged accept method of the ServerSocket class in the Common ObjectRequest Broker Architecture (CORBA) implementation in OpenJDK allowed it toreceive connections from any host, instead of just the host of the currentconnection. An attacker could use this flaw to bypass restrictions definedby network permissions. (CVE-2010-3561)Flaws in the Swing library could allow an untrusted application to modifythe behavior and state of certain JDK classes. (CVE-2010-3557)Flaws in the CORBA implementation could allow an attacker to executearbitrary code by misusing permissions granted to certain system objects.(CVE-2010-3554)UIDefault.ProxyLazyValue had unsafe reflection usage, allowing untrustedcallers to create objects via ProxyLazyValue values. (CVE-2010-3553)HttpURLConnection improperly handled the "chunked" transfer encodingmethod, which could allow remote attackers to conduct HTTP responsesplitting attacks. (CVE-2010-3549)HttpURLConnection improperly checked whether the calling code was grantedthe "allowHttpTrace" permission, allowing untrusted code to create HTTPTRACE requests. (CVE-2010-3574)HttpURLConnection did not validate request headers set by applets, whichcould allow remote attackers to trigger actions otherwise restricted toHTTP clients. (CVE-2010-3541, CVE-2010-3573)The Kerberos implementation improperly checked the sanity of AP-REQrequests, which could cause a denial of service condition in the receivingJava Virtual Machine. (CVE-2010-3564)The java-1.6.0-openjdk packages shipped with the GA release of Red HatEnterprise Linux 6 mitigated a man-in-the-middle attack in the way theTLS/SSL protocols handle session renegotiation by disabling renegotiation.This update implements the TLS Renegotiation Indication Extension asdefined in RFC 5746, allowing secure renegotiation between updated clientsand servers. (CVE-2009-3555)The NetworkInterface class improperly checked the network "connect"permissions for local network addresses, which could allow remote attackersto read local network addresses. (CVE-2010-3551)Information leak flaw in the Java Naming and Directory Interface (JNDI)could allow a remote attacker to access information aboutotherwise-protected internal network names. (CVE-2010-3548)Note: Flaws concerning applets in this advisory (CVE-2010-3568,CVE-2010-3554, CVE-2009-3555, CVE-2010-3562, CVE-2010-3557, CVE-2010-3548,CVE-2010-3564, CVE-2010-3565, CVE-2010-3569) can only be triggered inOpenJDK by calling the "appletviewer" application.Bug fixes: One defense in depth patch. (BZ#639922) Problems for certain SSL connections. In a reported case, this prevented the JBoss JAAS modules from connecting over SSL to Microsoft ActiveDirectory servers. (BZ#642779)

Affected Software

12 affected componentsFixes available
redhat/java<1.6.0-openjdk-1.6.0.0-1.31.b17.el6_0
1.6.0-openjdk-1.6.0.0-1.31.b17.el6_0
redhat/java<1.6.0-openjdk-1.6.0.0-1.31.b17.el6_0
1.6.0-openjdk-1.6.0.0-1.31.b17.el6_0
redhat/java<1.6.0-openjdk-debuginfo-1.6.0.0-1.31.b17.el6_0
1.6.0-openjdk-debuginfo-1.6.0.0-1.31.b17.el6_0
redhat/java<1.6.0-openjdk-demo-1.6.0.0-1.31.b17.el6_0
1.6.0-openjdk-demo-1.6.0.0-1.31.b17.el6_0
redhat/java<1.6.0-openjdk-devel-1.6.0.0-1.31.b17.el6_0
1.6.0-openjdk-devel-1.6.0.0-1.31.b17.el6_0
redhat/java<1.6.0-openjdk-javadoc-1.6.0.0-1.31.b17.el6_0
1.6.0-openjdk-javadoc-1.6.0.0-1.31.b17.el6_0
redhat/java<1.6.0-openjdk-src-1.6.0.0-1.31.b17.el6_0
1.6.0-openjdk-src-1.6.0.0-1.31.b17.el6_0
redhat/java<1.6.0-openjdk-debuginfo-1.6.0.0-1.31.b17.el6_0
1.6.0-openjdk-debuginfo-1.6.0.0-1.31.b17.el6_0
redhat/java<1.6.0-openjdk-demo-1.6.0.0-1.31.b17.el6_0
1.6.0-openjdk-demo-1.6.0.0-1.31.b17.el6_0
redhat/java<1.6.0-openjdk-devel-1.6.0.0-1.31.b17.el6_0
1.6.0-openjdk-devel-1.6.0.0-1.31.b17.el6_0
redhat/java<1.6.0-openjdk-javadoc-1.6.0.0-1.31.b17.el6_0
1.6.0-openjdk-javadoc-1.6.0.0-1.31.b17.el6_0
redhat/java<1.6.0-openjdk-src-1.6.0.0-1.31.b17.el6_0
1.6.0-openjdk-src-1.6.0.0-1.31.b17.el6_0

Remediation

Event History

Nov 10, 2010
Advisory Published
via Red Hat·12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2010:0865?

The severity of RHSA-2010:0865 is classified as important due to potential remote code execution risks.

2

How do I fix RHSA-2010:0865?

To fix RHSA-2010:0865, update to the recommended version 1.6.0-openjdk-1.6.0.0-1.31.b17.el6_0.

3

What version of OpenJDK is affected by RHSA-2010:0865?

RHSA-2010:0865 affects OpenJDK versions prior to 1.6.0-openjdk-1.6.0.0-1.31.b17.el6_0.

4

What types of software packages does RHSA-2010:0865 affect?

RHSA-2010:0865 affects multiple OpenJDK packages including the runtime environment, SDK, debuginfo, demo, development, and javadoc packages.

5

Can RHSA-2010:0865 be exploited remotely?

Yes, RHSA-2010:0865 can be exploited remotely, allowing attackers to execute arbitrary code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203