RHSA-2015:1006: Critical: java-1.6.0-ibm security update
IBM Java SE version 6 includes the IBM Java Runtime Environment and the IBM<br>Java Software Development Kit.<br>This update fixes several vulnerabilities in the IBM Java Runtime<br>Environment and the IBM Java Software Development Kit. Further information<br>about these flaws can be found on the IBM Java Security alerts page, listed<br>in the References section. (CVE-2005-1080, CVE-2015-0138, CVE-2015-0192,<br>CVE-2015-0458, CVE-2015-0459, CVE-2015-0469, CVE-2015-0477, CVE-2015-0478,<br>CVE-2015-0480, CVE-2015-0488, CVE-2015-0491, CVE-2015-1914, CVE-2015-2808)<br>The CVE-2015-0478 issue was discovered by Florian Weimer of Red Hat<br>Product Security.<br>Note: With this update, the IBM JDK now disables RC4 SSL/TLS cipher suites<br>by default to address the CVE-2015-2808 issue. Refer to Red Hat Bugzilla<br>bug 1207101, linked to from the References section, for additional details<br>about this change.<br>All users of java-1.6.0-ibm are advised to upgrade to these updated<br>packages, containing the IBM Java SE 6 SR16-FP4 release. All running<br>instances of IBM Java must be restarted for the update to take effect.<br>
Affected Software
Remediation
Event History
Frequently Asked Questions
What are the main issues fixed in RHSA-2015:1006?
RHSA-2015:1006 addresses several vulnerabilities in IBM Java SE version 6, enhancing the security of the IBM Java Runtime Environment and the IBM Software Development Kit.
How does RHSA-2015:1006 impact system security?
The vulnerabilities fixed by RHSA-2015:1006 could potentially allow attackers to exploit weaknesses in the Java environment, leading to unauthorized access or system compromise.
What versions of IBM Java SE are affected by RHSA-2015:1006?
RHSA-2015:1006 impacts IBM Java SE version 6, specifically versions prior to 1.6.0-ibm-1.6.0.16.4-1jpp.1.el6_6 and 1.6.0-ibm-1.6.0.16.4-1jpp.1.el5.
How can I ensure compliance after applying RHSA-2015:1006?
To ensure compliance after applying RHSA-2015:1006, verify that all affected packages have been updated to the specified fixed versions as listed in the advisory.
What is the recommended action for RHSA-2015:1006?
The recommended action for RHSA-2015:1006 is to update the affected IBM Java SE packages to their latest versions as specified in the erratum.