RHSA-2009:1236: Critical: java-1.5.0-ibm security update
The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment andthe IBM Java 2 Software Development Kit.This update fixes several vulnerabilities in the IBM Java 2 RuntimeEnvironment and the IBM Java 2 Software Development Kit. Thesevulnerabilities are summarized on the IBM "Security alerts" page listed inthe References section. (CVE-2009-2625, CVE-2009-2670, CVE-2009-2671,CVE-2009-2672, CVE-2009-2673, CVE-2009-2675)All users of java-1.5.0-ibm are advised to upgrade to these updatedpackages, containing the IBM 1.5.0 SR10 Java release. All running instancesof IBM Java must be restarted for this update to take effect.Note: The packages included in this update are identical to the packagesmade available by RHEA-2009:1208 and RHEA-2009:1210 on the 13th ofAugust 2009. These packages are being reissued as a Red Hat SecurityAdvisory as they fixed a number of security issues that were not madepublic until after those errata were released. Since the packages areidentical, there is no need to install this update if RHEA-2009:1208 orRHEA-2009:1210 has already been installed.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:1236?
The vulnerability fixed by RHSA-2009:1236 is considered critical, impacting the security of applications utilizing IBM Java 2 Runtime Environment.
How do I fix RHSA-2009:1236?
To fix RHSA-2009:1236, users should update to the latest version of IBM Java specified in the advisory, namely 1.5.0-ibm-1.5.0.10-1jpp.4.el5.
What are the affected packages for RHSA-2009:1236?
RHSA-2009:1236 affects various IBM Java packages, including java, java-accessibility, java-demo, java-devel, java-javacomm, java-jdbc, java-plugin, and java-src.
Is RHSA-2009:1236 related to any specific Java version?
Yes, RHSA-2009:1236 specifically addresses vulnerabilities in IBM Java version 1.5.0.
What should I do if I cannot update my system for RHSA-2009:1236?
If you cannot update your system for RHSA-2009:1236, consider implementing workarounds or additional security measures to mitigate risks associated with the vulnerabilities.