java-1.6.0-openjdk-1.6.0.0-1.39.b17.AXS4

エラータID: AXSA:2011-61:02

リリース日: 
2011/02/24 Thursday - 13:30
題名: 
java-1.6.0-openjdk-1.6.0.0-1.39.b17.AXS4
影響のあるチャネル: 
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity: 
High
Description: 

The Java Platform Standard Edition Development Kit (JDK) includes both the runtime environment (Java virtual machine, the Java platform classes and supporting files) and development tools (compilers, debuggers, tool libraries and other tools).
The JDK is a development environment for building applications, applets and components that can be deployed with the Java Platform Standard Edition Runtime Environment.
Security issues fixed with this release:
CVE-2010-4448
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to Networking. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue involves DNS cache poisoning by untrusted applets.
CVE-2010-4450
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier for Solaris and Linux; 5.0 Update 27 and earlier for Solaris and Linux; and 1.4.2_29 and earlier for Solaris and Linux allows local standalone applications to affect confidentiality, integrity, and availability via unknown vectors related to Launcher. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is an untrusted search path vulnerability involving an empty LD_LIBRARY_PATH environment variable.
CVE-2010-4465
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is related to the lack of framework support by AWT event dispatch, and/or clipboard access in Applets.
CVE-2010-4469
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is heap corruption related to the Verifier and backward jsrs.
CVE-2010-4470
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23, and, and earlier allows remote attackers to affect availability via unknown vectors related to JAXP and unspecified APIs. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is related to Features set on SchemaFactory not inherited by Validator.
CVE-2010-4472
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect availability, related to XML Digital Signature and unspecified APIs. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue involves the replacement of the XML DSig Transform or C14N algorithm implementations.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. java-1.6.0-openjdk-1.6.0.0-1.39.b17.AXS4.src.rpm
    MD5: 90a593b26f53dd963bd67fd3e2aa2a34
    SHA-256: 9b997094b930116ba62f111694736764d6e086e930469e2b23c9d5cb7d3a0813
    Size: 56.48 MB

Asianux Server 4 for x86
  1. java-1.6.0-openjdk-1.6.0.0-1.39.b17.AXS4.i686.rpm
    MD5: d5db6682331dd0afd9acecede929a1b0
    SHA-256: af9a0272628da132bb1d1319485f0a2a4c25926c458e215e269d91898f7100db
    Size: 25.72 MB
  2. java-1.6.0-openjdk-devel-1.6.0.0-1.39.b17.AXS4.i686.rpm
    MD5: f49134de130d3d35afe5b3b6aecd903f
    SHA-256: 6f77eeaf7959872816a53346378ac012a0821ffc6fd60696064d4ca22189945a
    Size: 8.50 MB
  3. java-1.6.0-openjdk-javadoc-1.6.0.0-1.39.b17.AXS4.i686.rpm
    MD5: 6e4a089c0bd4c20c274fe4883336df69
    SHA-256: 5af4388b43725a7eb3c434053e02a93178fa59b96233237cc7602d884f5848b0
    Size: 14.37 MB

Asianux Server 4 for x86_64
  1. java-1.6.0-openjdk-1.6.0.0-1.39.b17.AXS4.x86_64.rpm
    MD5: 9d458e9ec25d9dcf4f4928fee6290457
    SHA-256: 48a9a1a4e93742a15c7e54f3aacf3a51c80846f9c7803ccb02222d558676112e
    Size: 24.61 MB
  2. java-1.6.0-openjdk-devel-1.6.0.0-1.39.b17.AXS4.x86_64.rpm
    MD5: 27bd217453546b341ee186dcf849c546
    SHA-256: b83a5216e794905cd5838b7745664a28cc289b22a166b7109aaf8d6ad25b0aec
    Size: 8.49 MB
  3. java-1.6.0-openjdk-javadoc-1.6.0.0-1.39.b17.AXS4.x86_64.rpm
    MD5: 57872e866fb0611e97b78b8c12ae54e3
    SHA-256: 9b4b059916f7ebbef1d9c591314530e3798bdd67a470622a05f7bdd908cf9779
    Size: 14.37 MB