Sun JDK/JRE: Multiple vulnerabilities Multiple vulnerabilities have been identified in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE). sun-jdk, sun-jre-bin, emul-linux-x86-java 2008-04-17 2010-03-05 178851 178962 183580 185256 194711 212425 remote 1.6.0.05 1.5.0.21 1.5.0.20 1.5.0.19 1.5.0.18 1.5.0.17 1.5.0.16 1.5.0.15 1.4.2.17 1.5.0.22 1.6.0.05 1.6.0.05 1.5.0.21 1.5.0.20 1.5.0.19 1.5.0.18 1.5.0.17 1.5.0.16 1.5.0.15 1.4.2.17 1.5.0.22 1.6.0.05 1.6.0.05 1.5.0.21 1.5.0.20 1.5.0.19 1.5.0.18 1.5.0.17 1.5.0.16 1.5.0.15 1.4.2.17 1.5.0.22 1.6.0.05

The Sun Java Development Kit (JDK) and the Sun Java Runtime Environment (JRE) provide the Sun Java platform.

Multiple vulnerabilities have been discovered in Sun Java:

A remote attacker could entice a user to run a specially crafted applet on a website or start an application in Java Web Start to execute arbitrary code outside of the Java sandbox and of the Java security restrictions with the privileges of the user running Java. The attacker could also obtain sensitive information, create, modify, rename and read local files, execute local applications, establish connections in the local network, bypass the same origin policy, and cause a Denial of Service via multiple vectors.

There is no known workaround at this time.

All Sun JRE 1.6 users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-java/sun-jre-bin-1.6.0.05"

All Sun JRE 1.5 users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-java/sun-jre-bin-1.5.0.15"

All Sun JRE 1.4 users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-java/sun-jre-bin-1.4.2.17"

All Sun JDK 1.6 users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-java/sun-jdk-1.6.0.05"

All Sun JDK 1.5 users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-java/sun-jdk-1.5.0.15"

All Sun JDK 1.4 users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-java/sun-jdk-1.4.2.17"

All emul-linux-x86-java 1.6 users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-emulation/emul-linux-x86-java-1.6.0.05"

All emul-linux-x86-java 1.5 users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-emulation/emul-linux-x86-java-1.5.0.15"

All emul-linux-x86-java 1.4 users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-emulation/emul-linux-x86-java-1.4.2.17"
CVE-2007-2435 CVE-2007-2788 CVE-2007-2789 CVE-2007-3655 CVE-2007-5232 CVE-2007-5237 CVE-2007-5238 CVE-2007-5239 CVE-2007-5240 CVE-2007-5273 CVE-2007-5274 CVE-2007-5689 CVE-2008-0628 CVE-2008-0657 CVE-2008-1185 CVE-2008-1186 CVE-2008-1187 CVE-2008-1188 CVE-2008-1189 CVE-2008-1190 CVE-2008-1191 CVE-2008-1192 CVE-2008-1193 CVE-2008-1194 CVE-2008-1195 CVE-2008-1196 GLSA 200705-23 GLSA 200706-08 jaervosz jaervosz rbu