RHEL 5 / 6:java-1.6.0-sun (RHSA-2014:0414)

medium Nessus 插件 ID 79011

简介

远程 Red Hat 主机缺少一个或多个安全更新。

描述

更新后的 java-1.6.0-sun 程序包修复了多个安全问题,现在可用于 Red Hat Enterprise Linux 5 和 6 的 Oracle Java。

Red Hat 安全响应团队已将此更新评级为具有重要安全影响。可从“参考”部分中的 CVE 链接获取针对每个漏洞的通用漏洞评分系统 (CVSS) 基本分数,其给出了详细的严重性等级。

[2014 年 5 月 12 日更新] 已更新此勘误表中的程序包列表,使程序包可在 Red Hat Network 的 Red Hat Enterprise Linux 6 工作站 x86_64 通道的 Oracle Java 中使用。

Oracle Java SE 版本 6 包括 Oracle Java Runtime Environment 和 Oracle Java 软件开发工具包。

此更新修复了 Oracle Java Runtime Environment 和 Oracle Java 软件开发工具包中的多个漏洞。有关这些缺陷的更多信息,请参阅“参考”部分的“Oracle Java SE 关键修补程序更新公告”页面。(CVE-2013-1500、CVE-2013-1571、CVE-2013-2407、CVE-2013-2412、CVE-2013-2437、CVE-2013-2442、CVE-2013-2443、CVE-2013-2444、CVE-2013-2445、CVE-2013-2446、CVE-2013-2447、CVE-2013-2448、CVE-2013-2450、CVE-2013-2451、CVE-2013-2452、CVE-2013-2453、CVE-2013-2454、CVE-2013-2455、CVE-2013-2456、CVE-2013-2457、CVE-2013-2459、CVE-2013-2461、CVE-2013-2463、CVE-2013-2464、CVE-2013-2465、CVE-2013-2466、CVE-2013-2468、CVE-2013-2469、CVE-2013-2470、CVE-2013-2471、CVE-2013-2472、CVE-2013-2473、CVE-2013-3743、CVE-2013-3829、CVE-2013-4002、CVE-2013-5772、CVE-2013-5774、CVE-2013-5776、CVE-2013-5778、CVE-2013-5780、CVE-2013-5782、CVE-2013-5783、CVE-2013-5784、CVE-2013-5787、CVE-2013-5789、CVE-2013-5790、CVE-2013-5797、CVE-2013-5801、CVE-2013-5802、CVE-2013-5803、CVE-2013-5804、CVE-2013-5809、CVE-2013-5812、CVE-2013-5814、CVE-2013-5817、CVE-2013-5818、CVE-2013-5819、CVE-2013-5820、CVE-2013-5823、CVE-2013-5824、CVE-2013-5825、CVE-2013-5829、CVE-2013-5830、CVE-2013-5831、CVE-2013-5832、CVE-2013-5840、CVE-2013-5842、CVE-2013-5843、CVE-2013-5848、CVE-2013-5849、CVE-2013-5850、CVE-2013-5852、CVE-2013-5878、CVE-2013-5884、CVE-2013-5887、CVE-2013-5888、CVE-2013-5889、CVE-2013-5896、CVE-2013-5898、CVE-2013-5899、CVE-2013-5902、CVE-2013-5905、CVE-2013-5906、CVE-2013-5907、CVE-2013-5910、CVE-2013-6629、CVE-2013-6954、CVE-2014-0368、CVE-2014-0373、CVE-2014-0375、CVE-2014-0376、CVE-2014-0387、CVE-2014-0403、CVE-2014-0410、CVE-2014-0411、CVE-2014-0415、CVE-2014-0416、CVE-2014-0417、CVE-2014-0418、CVE-2014-0422、CVE-2014-0423、CVE-2014-0424、CVE-2014-0428、CVE-2014-0429、CVE-2014-0446、CVE-2014-0449、CVE-2014-0451、CVE-2014-0452、CVE-2014-0453、CVE-2014-0456、CVE-2014-0457、CVE-2014-0458、CVE-2014-0460、CVE-2014-0461、CVE-2014-1876、CVE-2014-2398、CVE-2014-2401、CVE-2014-2403、CVE-2014-2409、CVE-2014-2412、CVE-2014-2414、CVE-2014-2420、CVE-2014-2421、CVE-2014-2423、CVE-2014-2427、CVE-2014-2428)

建议所有 java-1.6.0-sun 用户升级这些更新后的程序包,其中提供了 Oracle Java 6 Update 75 并解决了这些问题。必须重新启动所有正在运行的 Oracle Java 实例,才能使更新生效。

解决方案

更新受影响的数据包。

另见

https://www.redhat.com/security/data/cve/CVE-2013-2445.html

https://www.redhat.com/security/data/cve/CVE-2013-2446.html

https://www.redhat.com/security/data/cve/CVE-2013-2447.html

https://www.redhat.com/security/data/cve/CVE-2013-2448.html

https://www.redhat.com/security/data/cve/CVE-2013-2450.html

https://www.redhat.com/security/data/cve/CVE-2013-2451.html

https://www.redhat.com/security/data/cve/CVE-2013-2452.html

https://www.redhat.com/security/data/cve/CVE-2013-2453.html

https://www.redhat.com/security/data/cve/CVE-2013-2454.html

https://www.redhat.com/security/data/cve/CVE-2013-2455.html

https://www.redhat.com/security/data/cve/CVE-2013-2456.html

https://www.redhat.com/security/data/cve/CVE-2013-2457.html

https://www.redhat.com/security/data/cve/CVE-2013-2459.html

https://www.redhat.com/security/data/cve/CVE-2013-2461.html

https://www.redhat.com/security/data/cve/CVE-2013-2463.html

https://www.redhat.com/security/data/cve/CVE-2013-2464.html

https://www.redhat.com/security/data/cve/CVE-2013-5824.html

https://www.redhat.com/security/data/cve/CVE-2013-5825.html

https://www.redhat.com/security/data/cve/CVE-2013-5829.html

https://www.redhat.com/security/data/cve/CVE-2013-5830.html

https://www.redhat.com/security/data/cve/CVE-2013-5831.html

https://www.redhat.com/security/data/cve/CVE-2013-5832.html

https://www.redhat.com/security/data/cve/CVE-2013-5840.html

https://www.redhat.com/security/data/cve/CVE-2013-5842.html

https://www.redhat.com/security/data/cve/CVE-2013-5843.html

https://www.redhat.com/security/data/cve/CVE-2013-5848.html

https://www.redhat.com/security/data/cve/CVE-2013-5849.html

https://www.redhat.com/security/data/cve/CVE-2013-5850.html

https://www.redhat.com/security/data/cve/CVE-2013-5852.html

https://www.redhat.com/security/data/cve/CVE-2013-5878.html

https://www.redhat.com/security/data/cve/CVE-2013-5884.html

https://www.redhat.com/security/data/cve/CVE-2013-5887.html

https://www.redhat.com/security/data/cve/CVE-2013-5888.html

https://www.redhat.com/security/data/cve/CVE-2013-5889.html

https://www.redhat.com/security/data/cve/CVE-2013-5896.html

https://www.redhat.com/security/data/cve/CVE-2013-5898.html

https://www.redhat.com/security/data/cve/CVE-2013-5899.html

https://www.redhat.com/security/data/cve/CVE-2013-1500.html

https://www.redhat.com/security/data/cve/CVE-2013-1571.html

https://www.redhat.com/security/data/cve/CVE-2013-2407.html

https://www.redhat.com/security/data/cve/CVE-2013-2412.html

https://www.redhat.com/security/data/cve/CVE-2013-2437.html

https://www.redhat.com/security/data/cve/CVE-2013-2442.html

https://www.redhat.com/security/data/cve/CVE-2013-2443.html

https://www.redhat.com/security/data/cve/CVE-2013-2444.html

https://www.redhat.com/security/data/cve/CVE-2013-2465.html

https://www.redhat.com/security/data/cve/CVE-2013-2466.html

https://www.redhat.com/security/data/cve/CVE-2013-2468.html

https://www.redhat.com/security/data/cve/CVE-2013-2469.html

https://www.redhat.com/security/data/cve/CVE-2013-2470.html

https://www.redhat.com/security/data/cve/CVE-2013-2471.html

https://www.redhat.com/security/data/cve/CVE-2013-2472.html

https://www.redhat.com/security/data/cve/CVE-2013-2473.html

https://www.redhat.com/security/data/cve/CVE-2013-3743.html

https://www.redhat.com/security/data/cve/CVE-2013-3829.html

https://www.redhat.com/security/data/cve/CVE-2013-4002.html

https://www.redhat.com/security/data/cve/CVE-2013-5772.html

https://www.redhat.com/security/data/cve/CVE-2013-5774.html

https://www.redhat.com/security/data/cve/CVE-2013-5776.html

https://www.redhat.com/security/data/cve/CVE-2013-5778.html

https://www.redhat.com/security/data/cve/CVE-2013-5780.html

https://www.redhat.com/security/data/cve/CVE-2013-5782.html

https://www.redhat.com/security/data/cve/CVE-2013-5783.html

https://www.redhat.com/security/data/cve/CVE-2013-5784.html

https://www.redhat.com/security/data/cve/CVE-2013-5787.html

https://www.redhat.com/security/data/cve/CVE-2013-5789.html

https://www.redhat.com/security/data/cve/CVE-2013-5790.html

https://www.redhat.com/security/data/cve/CVE-2013-5797.html

https://www.redhat.com/security/data/cve/CVE-2013-5801.html

https://www.redhat.com/security/data/cve/CVE-2013-5802.html

https://www.redhat.com/security/data/cve/CVE-2013-5803.html

https://www.redhat.com/security/data/cve/CVE-2013-5804.html

https://www.redhat.com/security/data/cve/CVE-2013-5809.html

https://www.redhat.com/security/data/cve/CVE-2013-5812.html

https://www.redhat.com/security/data/cve/CVE-2013-5814.html

https://www.redhat.com/security/data/cve/CVE-2013-5817.html

https://www.redhat.com/security/data/cve/CVE-2013-5818.html

https://www.redhat.com/security/data/cve/CVE-2013-5819.html

https://www.redhat.com/security/data/cve/CVE-2013-5820.html

https://www.redhat.com/security/data/cve/CVE-2013-5823.html

https://www.redhat.com/security/data/cve/CVE-2014-0460.html

https://www.redhat.com/security/data/cve/CVE-2014-0461.html

https://www.redhat.com/security/data/cve/CVE-2014-1876.html

https://www.redhat.com/security/data/cve/CVE-2014-2398.html

https://www.redhat.com/security/data/cve/CVE-2014-2401.html

https://www.redhat.com/security/data/cve/CVE-2014-2403.html

https://www.redhat.com/security/data/cve/CVE-2014-2409.html

https://www.redhat.com/security/data/cve/CVE-2014-2412.html

https://www.redhat.com/security/data/cve/CVE-2014-2414.html

https://www.redhat.com/security/data/cve/CVE-2014-2420.html

https://www.redhat.com/security/data/cve/CVE-2014-2421.html

https://www.redhat.com/security/data/cve/CVE-2014-2423.html

https://www.redhat.com/security/data/cve/CVE-2014-2427.html

https://www.redhat.com/security/data/cve/CVE-2014-2428.html

http://www.nessus.org/u?a094a6d7

http://www.nessus.org/u?ac29c174

http://www.nessus.org/u?17c46362

http://www.nessus.org/u?ef1fc2a6

http://rhn.redhat.com/errata/RHSA-2014-0414.html

http://www.oracle.com/technetwork/topics/security/

https://www.redhat.com/security/data/cve/CVE-2013-5902.html

https://www.redhat.com/security/data/cve/CVE-2013-5905.html

https://www.redhat.com/security/data/cve/CVE-2013-5906.html

https://www.redhat.com/security/data/cve/CVE-2013-5907.html

https://www.redhat.com/security/data/cve/CVE-2013-5910.html

https://www.redhat.com/security/data/cve/CVE-2013-6629.html

https://www.redhat.com/security/data/cve/CVE-2013-6954.html

https://www.redhat.com/security/data/cve/CVE-2014-0368.html

https://www.redhat.com/security/data/cve/CVE-2014-0373.html

https://www.redhat.com/security/data/cve/CVE-2014-0375.html

https://www.redhat.com/security/data/cve/CVE-2014-0376.html

https://www.redhat.com/security/data/cve/CVE-2014-0387.html

https://www.redhat.com/security/data/cve/CVE-2014-0403.html

https://www.redhat.com/security/data/cve/CVE-2014-0410.html

https://www.redhat.com/security/data/cve/CVE-2014-0411.html

https://www.redhat.com/security/data/cve/CVE-2014-0415.html

https://www.redhat.com/security/data/cve/CVE-2014-0416.html

https://www.redhat.com/security/data/cve/CVE-2014-0417.html

https://www.redhat.com/security/data/cve/CVE-2014-0418.html

https://www.redhat.com/security/data/cve/CVE-2014-0422.html

https://www.redhat.com/security/data/cve/CVE-2014-0423.html

https://www.redhat.com/security/data/cve/CVE-2014-0424.html

https://www.redhat.com/security/data/cve/CVE-2014-0428.html

https://www.redhat.com/security/data/cve/CVE-2014-0429.html

https://www.redhat.com/security/data/cve/CVE-2014-0446.html

https://www.redhat.com/security/data/cve/CVE-2014-0449.html

https://www.redhat.com/security/data/cve/CVE-2014-0451.html

https://www.redhat.com/security/data/cve/CVE-2014-0452.html

https://www.redhat.com/security/data/cve/CVE-2014-0453.html

https://www.redhat.com/security/data/cve/CVE-2014-0456.html

https://www.redhat.com/security/data/cve/CVE-2014-0457.html

https://www.redhat.com/security/data/cve/CVE-2014-0458.html

插件详情

严重性: Medium

ID: 79011

文件名: redhat-RHSA-2014-0414.nasl

版本: 1.19

类型: local

代理: unix

发布时间: 2014/11/8

最近更新时间: 2023/4/25

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

风险信息

VPR

风险因素: Critical

分数: 9.8

CVSS v2

风险因素: Critical

基本分数: 10

时间分数: 8.7

矢量: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS 分数来源: CVE-2014-2421

CVSS v3

风险因素: Medium

基本分数: 5.3

时间分数: 5.1

矢量: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

时间矢量: CVSS:3.0/E:H/RL:O/RC:C

CVSS 分数来源: CVE-2013-4578

漏洞信息

CPE: p-cpe:/a:redhat:enterprise_linux:java-1.6.0-sun, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-sun-demo, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-sun-devel, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-sun-jdbc, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-sun-plugin, p-cpe:/a:redhat:enterprise_linux:java-1.6.0-sun-src, cpe:/o:redhat:enterprise_linux:5, cpe:/o:redhat:enterprise_linux:6, cpe:/o:redhat:enterprise_linux:6.5

必需的 KB 项: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

可利用: true

易利用性: Exploits are available

补丁发布日期: 2014/5/12

CISA 已知可遭利用的漏洞到期日期: 2022/4/18

可利用的方式

Core Impact

Metasploit (Java storeImageArray() Invalid Array Indexing Vulnerability)

参考资料信息

CVE: CVE-2013-1500, CVE-2013-1571, CVE-2013-2407, CVE-2013-2412, CVE-2013-2437, CVE-2013-2442, CVE-2013-2443, CVE-2013-2444, CVE-2013-2445, CVE-2013-2446, CVE-2013-2447, CVE-2013-2448, CVE-2013-2450, CVE-2013-2451, CVE-2013-2452, CVE-2013-2453, CVE-2013-2454, CVE-2013-2455, CVE-2013-2456, CVE-2013-2457, CVE-2013-2459, CVE-2013-2461, CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2466, CVE-2013-2468, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, CVE-2013-2472, CVE-2013-2473, CVE-2013-3743, CVE-2013-3829, CVE-2013-4002, CVE-2013-4578, CVE-2013-5772, CVE-2013-5774, CVE-2013-5776, CVE-2013-5778, CVE-2013-5780, CVE-2013-5782, CVE-2013-5783, CVE-2013-5784, CVE-2013-5787, CVE-2013-5789, CVE-2013-5790, CVE-2013-5797, CVE-2013-5801, CVE-2013-5802, CVE-2013-5803, CVE-2013-5804, CVE-2013-5809, CVE-2013-5812, CVE-2013-5814, CVE-2013-5817, CVE-2013-5818, CVE-2013-5819, CVE-2013-5820, CVE-2013-5823, CVE-2013-5824, CVE-2013-5825, CVE-2013-5829, CVE-2013-5830, CVE-2013-5831, CVE-2013-5832, CVE-2013-5840, CVE-2013-5842, CVE-2013-5843, CVE-2013-5848, CVE-2013-5849, CVE-2013-5850, CVE-2013-5852, CVE-2013-5878, CVE-2013-5884, CVE-2013-5887, CVE-2013-5888, CVE-2013-5889, CVE-2013-5896, CVE-2013-5898, CVE-2013-5899, CVE-2013-5902, CVE-2013-5905, CVE-2013-5906, CVE-2013-5907, CVE-2013-5910, CVE-2013-6629, CVE-2013-6954, CVE-2014-0368, CVE-2014-0373, CVE-2014-0375, CVE-2014-0376, CVE-2014-0387, CVE-2014-0403, CVE-2014-0410, CVE-2014-0411, CVE-2014-0415, CVE-2014-0416, CVE-2014-0417, CVE-2014-0418, CVE-2014-0422, CVE-2014-0423, CVE-2014-0424, CVE-2014-0428, CVE-2014-0429, CVE-2014-0446, CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876, CVE-2014-2398, CVE-2014-2401, CVE-2014-2403, CVE-2014-2409, CVE-2014-2412, CVE-2014-2414, CVE-2014-2420, CVE-2014-2421, CVE-2014-2423, CVE-2014-2427, CVE-2014-2428

RHSA: 2014:0414