Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.62896
Categoría:Red Hat Local Security Checks
Título:RedHat Security Advisory RHSA-2008:0594
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing updates announced in
advisory RHSA-2008:0594.

The Java Runtime Environment (JRE) contains the software and tools that
users need to run applets and applications written using the Java
programming language.

A vulnerability was found in the Java Management Extensions (JMX)
management agent, when local monitoring is enabled. This allowed remote
attackers to perform illegal operations. (CVE-2008-3103)

Multiple vulnerabilities with unsigned applets were reported. A remote
attacker could misuse an unsigned applet to connect to localhost services
running on the host running the applet. (CVE-2008-3104)

Several vulnerabilities in the Java API for XML Web Services (JAX-WS)
client and service implementation were found. A remote attacker who caused
malicious XML to be processed by a trusted or untrusted application was
able access URLs or cause a denial of service. (CVE-2008-3105, CVE-2008-3106)

A JRE vulnerability could be triggered by an untrusted application or
applet. A remote attacker could grant an untrusted applet or application
extended privileges such as being able to read and write local files, or
execute local programs. (CVE-2008-3107)

Several vulnerabilities within the JRE scripting support were reported. A
remote attacker could grant an untrusted applet extended privileges such as
reading and writing local files, executing local programs, or querying the
sensitive data of other applets. (CVE-2008-3109, CVE-2008-3110)

A vulnerability in Java Web Start was found. A remote attacker was able to
create arbitrary files with the permissions of the user running the
untrusted Java Web Start application. (CVE-2008-3112)

Another vulnerability in Java Web Start when processing untrusted
applications was reported. An attacker was able to acquire sensitive
information, such as the cache location. (CVE-2008-3114)

Users of java-1.6.0-sun should upgrade to these updated packages, which
correct these issues.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2008-0594.html
http://www.redhat.com/security/updates/classification/#critical

Risk factor : Critical

CVSS Score:
10.0

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2008-3103
http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.html
BugTraq ID: 30146
http://www.securityfocus.com/bid/30146
Bugtraq: 20081004 VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and (Google Search)
http://marc.info/?l=bugtraq&m=122331139823057&w=2
Bugtraq: 20081004 VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues (Google Search)
http://www.securityfocus.com/archive/1/497041/100/0/threaded
Cert/CC Advisory: TA08-193A
http://www.us-cert.gov/cas/techalerts/TA08-193A.html
http://security.gentoo.org/glsa/glsa-200911-02.xml
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10920
http://www.redhat.com/support/errata/RHSA-2008-0594.html
http://www.redhat.com/support/errata/RHSA-2008-0595.html
http://www.redhat.com/support/errata/RHSA-2008-0891.html
http://www.redhat.com/support/errata/RHSA-2008-0906.html
http://www.redhat.com/support/errata/RHSA-2008-1044.html
http://www.redhat.com/support/errata/RHSA-2008-1045.html
RedHat Security Advisories: RHSA-2009:0466
https://rhn.redhat.com/errata/RHSA-2009-0466.html
http://www.securitytracker.com/id?1020458
http://secunia.com/advisories/31010
http://secunia.com/advisories/31055
http://secunia.com/advisories/31497
http://secunia.com/advisories/31600
http://secunia.com/advisories/32018
http://secunia.com/advisories/32179
http://secunia.com/advisories/32180
http://secunia.com/advisories/32394
http://secunia.com/advisories/32436
http://secunia.com/advisories/32437
http://secunia.com/advisories/33237
http://secunia.com/advisories/33238
http://secunia.com/advisories/34972
http://secunia.com/advisories/37386
http://sunsolve.sun.com/search/document.do?assetkey=1-66-238965-1
SuSE Security Announcement: SUSE-SA:2008:042 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.html
SuSE Security Announcement: SUSE-SR:2008:022 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00009.html
http://www.vupen.com/english/advisories/2008/2056/references
http://www.vupen.com/english/advisories/2008/2740
XForce ISS Database: sun-jmx-security-bypass(43669)
https://exchange.xforce.ibmcloud.com/vulnerabilities/43669
Common Vulnerability Exposure (CVE) ID: CVE-2008-3104
BugTraq ID: 30140
http://www.securityfocus.com/bid/30140
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9565
http://www.redhat.com/support/errata/RHSA-2008-0790.html
RedHat Security Advisories: RHSA-2008:0955
http://rhn.redhat.com/errata/RHSA-2008-0955.html
http://www.redhat.com/support/errata/RHSA-2008-1043.html
http://www.securitytracker.com/id?1020459
http://secunia.com/advisories/31269
http://secunia.com/advisories/31320
http://secunia.com/advisories/31736
http://secunia.com/advisories/32826
http://secunia.com/advisories/33194
http://secunia.com/advisories/33236
http://secunia.com/advisories/35065
http://sunsolve.sun.com/search/document.do?assetkey=1-66-238968-1
SuSE Security Announcement: SUSE-SA:2008:043 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00000.html
SuSE Security Announcement: SUSE-SA:2008:045 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00002.html
SuSE Security Announcement: SUSE-SR:2008:028 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00003.html
SuSE Security Announcement: SUSE-SR:2009:010 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
XForce ISS Database: sun-jre-unspecified-security-bypass(43662)
https://exchange.xforce.ibmcloud.com/vulnerabilities/43662
Common Vulnerability Exposure (CVE) ID: CVE-2008-3105
http://lists.apple.com/archives/security-announce//2008/Sep/msg00007.html
BugTraq ID: 30143
http://www.securityfocus.com/bid/30143
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11274
http://www.securitytracker.com/id?1020457
http://sunsolve.sun.com/search/document.do?assetkey=1-66-238628-1
XForce ISS Database: sun-jre-jaxws-unauth-access(43654)
https://exchange.xforce.ibmcloud.com/vulnerabilities/43654
XForce ISS Database: sun-jre-xml-dos(43657)
https://exchange.xforce.ibmcloud.com/vulnerabilities/43657
Common Vulnerability Exposure (CVE) ID: CVE-2008-3106
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10866
XForce ISS Database: sun-jre-xml-unauth-access(43658)
https://exchange.xforce.ibmcloud.com/vulnerabilities/43658
Common Vulnerability Exposure (CVE) ID: CVE-2008-3107
BugTraq ID: 30141
http://www.securityfocus.com/bid/30141
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10219
http://www.securitytracker.com/id?1020455
http://sunsolve.sun.com/search/document.do?assetkey=1-66-238967-1
XForce ISS Database: sun-virtualmachine-unauth-access(43659)
https://exchange.xforce.ibmcloud.com/vulnerabilities/43659
Common Vulnerability Exposure (CVE) ID: CVE-2008-3109
BugTraq ID: 30144
http://www.securityfocus.com/bid/30144
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8540
http://www.securitytracker.com/id?1020456
http://sunsolve.sun.com/search/document.do?assetkey=1-66-238687-1
XForce ISS Database: sun-jre-scripting-unauth-access(43660)
https://exchange.xforce.ibmcloud.com/vulnerabilities/43660
Common Vulnerability Exposure (CVE) ID: CVE-2008-3110
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10734
XForce ISS Database: sun-jre-scripting-info-disclosure(43661)
https://exchange.xforce.ibmcloud.com/vulnerabilities/43661
Common Vulnerability Exposure (CVE) ID: CVE-2008-3112
BugTraq ID: 30148
http://www.securityfocus.com/bid/30148
http://www.zerodayinitiative.com/advisories/ZDI-08-042/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11102
http://www.securitytracker.com/id?1020452
http://sunsolve.sun.com/search/document.do?assetkey=1-66-238905-1
XForce ISS Database: sun-javawebstart-file-create(43666)
https://exchange.xforce.ibmcloud.com/vulnerabilities/43666
Common Vulnerability Exposure (CVE) ID: CVE-2008-3114
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9755
XForce ISS Database: sun-javawebstart-cache-info-disclosure(43668)
https://exchange.xforce.ibmcloud.com/vulnerabilities/43668
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.