java-1.6.0-openjdk-1.6.0.0-1.61.1.11.11.AXS4

エラータID: AXSA:2013-428:03

Release date: 
Friday, May 3, 2013 - 15:21
Subject: 
java-1.6.0-openjdk-1.6.0.0-1.61.1.11.11.AXS4
Affected Channels: 
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity: 
High
Description: 

The OpenJDK runtime environment.

Security issues fixed with this release:

• CVE-2013-0401
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier allows remote attackers to execute arbitrary code via vectors related to AWT, as demonstrated by Ben Murphy during a Pwn2Own competition at CanSecWest 2013.

• CVE-2013-1488
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allows remote attackers to execute arbitrary code via unspecified vectors involving reflection and Libraries, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.

• CVE-2013-1518
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXP.

• CVE-2013-1537
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI.

• CVE-2013-1557
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI.

• CVE-2013-1558
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans.

• CVE-2013-1569
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2383, CVE-2013-2384, and CVE-2013-2420.

• CVE-2013-2383
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2384, and CVE-2013-2420.

• CVE-2013-2384
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2383, and CVE-2013-2420.

• CVE-2013-2415
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allows local users to affect confidentiality via vectors related to JAX-WS.

• CVE-2013-2417
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier allows remote attackers to affect availability via unknown vectors related to Networking.

• CVE-2013-2419
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier allows remote attackers to affect availability via unknown vectors related to 2D.

• CVE-2013-2420
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2383, and CVE-2013-2384.

• CVE-2013-2421
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.

• CVE-2013-2422
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

• CVE-2013-2424
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier allows remote attackers to affect confidentiality via vectors related to JMX.

• CVE-2013-2426
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-1488 and CVE-2013-2436.

• CVE-2013-2429
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO.

• CVE-2013-2430
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO.

• CVE-2013-2431
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. java-1.6.0-openjdk-1.6.0.0-1.61.1.11.11.AXS4.src.rpm
    MD5: 4141ac9b26db90c912e5730cc9560d35
    SHA-256: 7142e115f771647ea7b191a52194f4f7e9f8ceb15d9acb2a6dfedaaee6f9925e
    Size: 55.71 MB

Asianux Server 4 for x86
  1. java-1.6.0-openjdk-1.6.0.0-1.61.1.11.11.AXS4.i686.rpm
    MD5: c2680b17df404357dc1ef32979e72543
    SHA-256: 49b371ea6d904bef7fb4d89274be567d5628f1e2ec7cba8bd62c0e94ccc5183b
    Size: 26.12 MB
  2. java-1.6.0-openjdk-devel-1.6.0.0-1.61.1.11.11.AXS4.i686.rpm
    MD5: f386bfa4aa6870e069ccc2467dcc7c10
    SHA-256: 11ffebe68ae9e9a408c61758fe0c23e7395d29a45cdcaa6948bb49d5dfe11aed
    Size: 8.54 MB
  3. java-1.6.0-openjdk-javadoc-1.6.0.0-1.61.1.11.11.AXS4.i686.rpm
    MD5: de78e9a5fe6a5b4a09bcd9fc62903227
    SHA-256: c58cb68ad35f66ae47107beef6362e7fbe4818349caa4119d5ec94fd2c8638e0
    Size: 14.38 MB

Asianux Server 4 for x86_64
  1. java-1.6.0-openjdk-1.6.0.0-1.61.1.11.11.AXS4.x86_64.rpm
    MD5: 4aef42fd2761499d4bbddacfe16383bb
    SHA-256: f2c55e1ef90f83e296fab320fcd70931ecbde7d586ccabf285b76c9b8238c53c
    Size: 25.14 MB
  2. java-1.6.0-openjdk-devel-1.6.0.0-1.61.1.11.11.AXS4.x86_64.rpm
    MD5: 441c46433dbaa69a4dfa3529816b066c
    SHA-256: e16f12974f1c89e231102cd0afbbba42f59f60577254a10e21fb6aa9f724e735
    Size: 8.53 MB
  3. java-1.6.0-openjdk-javadoc-1.6.0.0-1.61.1.11.11.AXS4.x86_64.rpm
    MD5: fd552ab1c8eba08b7186c3c87076e2fd
    SHA-256: 703b3239eb47a5a22f5ed8dd1aee7c3225c37422b8cf6ca899f7e07c9e03e8e0
    Size: 14.37 MB