<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat Errata System</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2011-09-30T09:28:08</oval:timestamp>
  </generator>

  <definitions>
    <definition id="oval:com.redhat.rhsa:def:20091694" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1694: java-1.6.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1694-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1694.html"/>
          <reference source="CVE" ref_id="CVE-2009-0217" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0217.html"/>
          <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
          <reference source="CVE" ref_id="CVE-2009-3865" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3865.html"/>
          <reference source="CVE" ref_id="CVE-2009-3866" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3866.html"/>
          <reference source="CVE" ref_id="CVE-2009-3867" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3867.html"/>
          <reference source="CVE" ref_id="CVE-2009-3868" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3868.html"/>
          <reference source="CVE" ref_id="CVE-2009-3869" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3869.html"/>
          <reference source="CVE" ref_id="CVE-2009-3871" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3871.html"/>
          <reference source="CVE" ref_id="CVE-2009-3872" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3872.html"/>
          <reference source="CVE" ref_id="CVE-2009-3873" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3873.html"/>
          <reference source="CVE" ref_id="CVE-2009-3874" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3874.html"/>
          <reference source="CVE" ref_id="CVE-2009-3875" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3875.html"/>
          <reference source="CVE" ref_id="CVE-2009-3876" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3876.html"/>
          <reference source="CVE" ref_id="CVE-2009-3877" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3877.html"/>
    
    <description>The IBM 1.6.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. These
vulnerabilities are summarized on the IBM &quot;Security alerts&quot; page listed in
the References section. (CVE-2009-0217, CVE-2009-3865, CVE-2009-3866,
CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3872,
CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, CVE-2009-3877)

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.6.0 SR7 Java release. All running instances
of IBM Java must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-23"/>
        <updated date="2009-12-23"/>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0217.html">CVE-2009-0217</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3555.html">CVE-2009-3555</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3865.html">CVE-2009-3865</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3866.html">CVE-2009-3866</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3867.html">CVE-2009-3867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3868.html">CVE-2009-3868</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3869.html">CVE-2009-3869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3871.html">CVE-2009-3871</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3872.html">CVE-2009-3872</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3873.html">CVE-2009-3873</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3874.html">CVE-2009-3874</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3875.html">CVE-2009-3875</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3876.html">CVE-2009-3876</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3877.html">CVE-2009-3877</cve>
                <bugzilla href="http://bugzilla.redhat.com/511915" id="511915">CVE-2009-0217 xmlsec1, mono, xml-security-c, xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530053" id="530053">CVE-2009-3873 OpenJDK JPEG Image Writer quantization problem (6862968)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530057" id="530057">CVE-2009-3875 OpenJDK MessageDigest.isEqual introduces timing attack vulnerabilities  (6863503)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530061" id="530061">CVE-2009-3876 OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530062" id="530062">CVE-2009-3869 OpenJDK JRE AWT setDifflCM stack overflow (6872357)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530063" id="530063">CVE-2009-3871 OpenJDK JRE AWT setBytePixels heap overflow (6872358)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530067" id="530067">CVE-2009-3874 OpenJDK ImageI/O JPEG heap overflow  (6874643)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/532906" id="532906">CVE-2009-3872 JRE JPEG JFIF Decoder issue (6862969)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533211" id="533211">CVE-2009-3865 java-1.6.0-sun: ACE in JRE Deployment Toolkit (6869752)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533212" id="533212">CVE-2009-3866 java-1.6.0-sun: Privilege escalation in the Java Web Start Installer  (6872824)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533214" id="533214">CVE-2009-3867 java-1.5.0-sun, java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533215" id="533215">CVE-2009-3868 java-1.5.0-sun, java-1.6.0-sun: Privilege escalation via crafted image file due improper color profiles parsing (6862970)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694010" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091694011" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694002" comment="java-1.6.0-ibm is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091694003" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694016" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091694017" comment="java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694012" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091694013" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694014" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091694015" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694004" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091694005" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694008" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091694009" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694006" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091694007" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
  </definitions>
  <tests>
    <!-- ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ -->
    <rpminfo_test id="oval:com.redhat.rhsa:tst:20091694001"  version="502" comment="Red Hat Enterprise Linux 5 is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694003" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694002"  version="502" comment="java-1.6.0-ibm is earlier than 1:1.6.0.7-1jpp.2.el5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694004" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694003"  version="502" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694004"  version="502" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.7-1jpp.2.el5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694004" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694005"  version="502" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694006"  version="502" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.7-1jpp.2.el5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694004" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694007"  version="502" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694008"  version="502" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.7-1jpp.2.el5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694004" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694009"  version="502" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694010"  version="502" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.7-1jpp.2.el5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694004" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694011"  version="502" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694012"  version="502" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.7-1jpp.2.el5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694004" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694013"  version="502" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694014"  version="502" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.7-1jpp.2.el5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694004" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694015"  version="502" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694002" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694016"  version="502" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.7-1jpp.2.el5" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694004" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20091694017"  version="502" comment="java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20091694009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091694002" />
</rpminfo_test>

  </tests>

  <objects>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ -->
    <rpminfo_object id="oval:com.redhat.rhsa:obj:20091694006"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>java-1.6.0-ibm-javacomm</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20091694001"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20091694002"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>java-1.6.0-ibm</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20091694009"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>java-1.6.0-ibm-accessibility</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20091694007"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>java-1.6.0-ibm-devel</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20091694008"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>java-1.6.0-ibm-src</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20091694003"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>java-1.6.0-ibm-demo</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20091694005"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>java-1.6.0-ibm-plugin</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20091694004"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>java-1.6.0-ibm-jdbc</name>
</rpminfo_object>

  </objects>
  <states>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ -->
    <rpminfo_state id="oval:com.redhat.rhsa:ste:20091694001"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <signature_keyid  operation="equals">219180cddb42a60e</signature_keyid>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20091694002"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <signature_keyid  operation="equals">5326810137017186</signature_keyid>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20091694003"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <version  operation="pattern match">^5[^[:digit:]]</version>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20091694004"  version="502" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <evr datatype="evr_string" operation="less than">1:1.6.0.7-1jpp.2.el5</evr>
</rpminfo_state>

  </states>
</oval_definitions>


