First published: Thu Dec 05 2013(Updated: )
This update corrects several security vulnerabilities in the IBM Java<br>Runtime Environment shipped as part of Red Hat Network Satellite Server<br>5.4, 5.5 and 5.6. In a typical operating environment, these are of low<br>security risk as the runtime is not used on untrusted applets.<br>Several flaws were fixed in the IBM Java 2 Runtime Environment.<br>(CVE-2013-3829, CVE-2013-4041, CVE-2013-5372, CVE-2013-5375, CVE-2013-5457,<br>CVE-2013-5772, CVE-2013-5774, CVE-2013-5776, CVE-2013-5778, CVE-2013-5780,<br>CVE-2013-5782, CVE-2013-5783, CVE-2013-5784, CVE-2013-5787, CVE-2013-5789,<br>CVE-2013-5797, CVE-2013-5801, CVE-2013-5802, CVE-2013-5803, CVE-2013-5804,<br>CVE-2013-5809, CVE-2013-5812, CVE-2013-5814, CVE-2013-5817, CVE-2013-5818,<br>CVE-2013-5819, CVE-2013-5820, CVE-2013-5823, CVE-2013-5824, CVE-2013-5825,<br>CVE-2013-5829, CVE-2013-5830, CVE-2013-5831, CVE-2013-5832, CVE-2013-5840,<br>CVE-2013-5842, CVE-2013-5843, CVE-2013-5848, CVE-2013-5849, CVE-2013-5850,<br>CVE-2013-5851)<br>Users of Red Hat Network Satellite Server 5.4, 5.5 and 5.6 are advised to<br>upgrade to these updated packages, which contain the IBM Java SE 6 SR15<br>release. For this update to take effect, Red Hat Network Satellite Server<br>must be restarted ("/usr/sbin/rhn-satellite restart"), as well as all<br>running instances of IBM Java.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.6.0-ibm-1.6.0.15.0-1jpp.1.el6 | 1.6.0-ibm-1.6.0.15.0-1jpp.1.el6 |
redhat/java | <1.6.0-ibm-1.6.0.15.0-1jpp.1.el6 | 1.6.0-ibm-1.6.0.15.0-1jpp.1.el6 |
redhat/java | <1.6.0-ibm-devel-1.6.0.15.0-1jpp.1.el6 | 1.6.0-ibm-devel-1.6.0.15.0-1jpp.1.el6 |
redhat/java | <1.6.0-ibm-devel-1.6.0.15.0-1jpp.1.el6 | 1.6.0-ibm-devel-1.6.0.15.0-1jpp.1.el6 |
redhat/java | <1.6.0-ibm-1.6.0.15.0-1jpp.1.el5 | 1.6.0-ibm-1.6.0.15.0-1jpp.1.el5 |
redhat/java | <1.6.0-ibm-1.6.0.15.0-1jpp.1.el5 | 1.6.0-ibm-1.6.0.15.0-1jpp.1.el5 |
redhat/java | <1.6.0-ibm-devel-1.6.0.15.0-1jpp.1.el5 | 1.6.0-ibm-devel-1.6.0.15.0-1jpp.1.el5 |
redhat/java | <1.6.0-ibm-devel-1.6.0.15.0-1jpp.1.el5 | 1.6.0-ibm-devel-1.6.0.15.0-1jpp.1.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2013:1793 is considered low in a typical operating environment.
To fix RHSA-2013:1793, update the affected IBM Java packages to version 1.6.0-ibm-1.6.0.15.0-1jpp.1.el5 or el6.
RHSA-2013:1793 affects Red Hat Network Satellite Server versions 5.4, 5.5, and 5.6.
No, the runtime is not typically used on untrusted applets, limiting security risk.
Yes, the specific packages mentioned include java and java-devel versions 1.6.0-ibm.