jdk-1.6.0_41
エラータID: AXSA:2013-103:02
リリース日:
2013/03/04 Monday - 21:35
題名:
jdk-1.6.0_41
影響のあるチャネル:
Asianux Server 3 for x86_64
Asianux Server 3 for x86
Severity:
High
Description:
バグフィックスが施された jdk-1.6.0_41 がリリースされました。
詳細については、以下の URL を参照してください。
http://www.oracle.com/technetwork/java/javase/6u41-relnotes-1907743.html
解決策:
1. 以下の URL から JDK 6 Update 41 をダウンロードしてください。
http://www.oracle.com/technetwork/java/javase/downloads/jdk6downloads-19...
[Asianux Server 3]
jdk-6u41-linux-i586-rpm.bin
[Asianux Server 3 for x86-64]
jdk-6u41-linux-x64-rpm.bin
2. 以下のコマンドを実行してインストールしてください。
[Asianux Server 3]
# sh jdk-6u41-linux-i586-rpm.bin
[Asianux Server 3 for x86-64]
# sh jdk-6u41-linux-x64-rpm.bin
CVE:
CVE-2013-0169
The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.
The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.
CVE-2013-1487
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE 7 Update 13 and earlier and 6 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE 7 Update 13 and earlier and 6 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
追加情報:
N/A
ダウンロード: