<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat Errata System</oval:product_name>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2012-06-13T16:02:07</oval:timestamp>
  </generator>

  <definitions>
    <definition id="oval:com.redhat.rhsa:def:20120734" version="501" class="patch">
      <metadata>
        <title>RHSA-2012:0734: java-1.6.0-sun security update (Critical)</title>
    <affected family="unix">
      <platform>Supplementary for Red Hat Enterprise Linux 6</platform>
    </affected>
    <reference source="RHSA" ref_id="RHSA-2012:0734-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0734.html"/>
      <reference source="CVE" ref_id="CVE-2012-0551" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0551.html"/>
      <reference source="CVE" ref_id="CVE-2012-1711" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1711.html"/>
      <reference source="CVE" ref_id="CVE-2012-1713" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1713.html"/>
      <reference source="CVE" ref_id="CVE-2012-1716" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1716.html"/>
      <reference source="CVE" ref_id="CVE-2012-1717" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1717.html"/>
      <reference source="CVE" ref_id="CVE-2012-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1718.html"/>
      <reference source="CVE" ref_id="CVE-2012-1719" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1719.html"/>
      <reference source="CVE" ref_id="CVE-2012-1721" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1721.html"/>
      <reference source="CVE" ref_id="CVE-2012-1722" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1722.html"/>
      <reference source="CVE" ref_id="CVE-2012-1723" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1723.html"/>
      <reference source="CVE" ref_id="CVE-2012-1724" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1724.html"/>
      <reference source="CVE" ref_id="CVE-2012-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1725.html"/>
    <description>The Sun 1.6.0 Java release includes the Sun Java 6 Runtime Environment and
the Sun Java 6 Software Development Kit.

This update fixes several vulnerabilities in the Sun Java 6 Runtime
Environment and the Sun Java 6 Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch page, listed in the References section. (CVE-2012-0551,
CVE-2012-1711, CVE-2012-1713, CVE-2012-1716, CVE-2012-1717, CVE-2012-1718,
CVE-2012-1719, CVE-2012-1721, CVE-2012-1722, CVE-2012-1723, CVE-2012-1724,
CVE-2012-1725)

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide JDK and JRE 6 Update 33 and resolve these issues.
All running instances of Sun Java must be restarted for the update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2012 Red Hat, Inc.</rights>
        <issued date="2012-06-13"/>
        <updated date="2012-06-13"/>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2012-0551.html">CVE-2012-0551</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2012-1711.html">CVE-2012-1711</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2012-1713.html">CVE-2012-1713</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2012-1716.html">CVE-2012-1716</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2012-1717.html">CVE-2012-1717</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2012-1718.html">CVE-2012-1718</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2012-1719.html">CVE-2012-1719</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2012-1721.html">CVE-2012-1721</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2012-1722.html">CVE-2012-1722</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2012-1723.html">CVE-2012-1723</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2012-1724.html">CVE-2012-1724</cve>
        <cve href="https://www.redhat.com/security/data/cve/CVE-2012-1725.html">CVE-2012-1725</cve>
        <bugzilla href="http://bugzilla.redhat.com/829354" id="829354">CVE-2012-1711 OpenJDK: improper protection of CORBA data models (CORBA, 7079902)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/829358" id="829358">CVE-2012-1717 OpenJDK: insecure temporary file permissions (JRE, 7143606)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/829360" id="829360">CVE-2012-1716 OpenJDK: SynthLookAndFeel application context bypass (Swing, 7143614)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/829361" id="829361">CVE-2012-1713 OpenJDK: fontmanager layout lookup code memory corruption (2D, 7143617)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/829371" id="829371">CVE-2012-1719 OpenJDK: mutable repository identifiers in generated stub code (CORBA, 7143851)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/829372" id="829372">CVE-2012-1718 OpenJDK: CRL and certificate extensions handling improvements (Security, 7143872)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/829373" id="829373">CVE-2012-1723 OpenJDK: insufficient field accessibility checks (HotSpot, 7152811)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/829374" id="829374">CVE-2012-1724 OpenJDK: XML parsing infinite loop (JAXP, 7157609)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/829376" id="829376">CVE-2012-1725 OpenJDK: insufficient invokespecial &lt;init&gt; verification (HotSpot, 7160757)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/831353" id="831353">CVE-2012-1721 Oracle JDK: unspecified vulnerability fixed in 6u33 and 7u5 (Deployment)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/831354" id="831354">CVE-2012-1722 Oracle JDK: unspecified vulnerability fixed in 6u33 and 7u5 (Deployment)</bugzilla>
        <bugzilla href="http://bugzilla.redhat.com/831355" id="831355">CVE-2012-0551 Oracle JDK: unspecified vulnerability fixed in 6u33 and 7u5 (Deployment)</bugzilla>
    <affected_cpe_list>
        <cpe>cpe:/a:redhat:rhel_extras</cpe>
    </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 
 <criteria operator="OR">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20120734001" comment="Red Hat Enterprise Linux 6 Client is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20120734002" comment="Red Hat Enterprise Linux 6 Server is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20120734003" comment="Red Hat Enterprise Linux 6 Workstation is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20120734004" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" />
 
</criteria>
<criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20120734011" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.33-1jpp.1.el6_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20120734012" comment="java-1.6.0-sun-demo is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20120734015" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.33-1jpp.1.el6_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20120734016" comment="java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20120734013" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.33-1jpp.1.el6_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20120734014" comment="java-1.6.0-sun-src is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20120734005" comment="java-1.6.0-sun is earlier than 1:1.6.0.33-1jpp.1.el6_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20120734006" comment="java-1.6.0-sun is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20120734009" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.33-1jpp.1.el6_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20120734010" comment="java-1.6.0-sun-plugin is signed with Red Hat redhatrelease2 key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20120734007" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.33-1jpp.1.el6_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20120734008" comment="java-1.6.0-sun-devel is signed with Red Hat redhatrelease2 key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
  </definitions>
  <tests>
    <!-- ~~~~~~~~~~~~~~~~~~~~~   rpminfo tests   ~~~~~~~~~~~~~~~~~~~~~ -->
    <rpminfo_test id="oval:com.redhat.rhsa:tst:20120734001"  version="501" comment="Red Hat Enterprise Linux 6 Client is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734003" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734002"  version="501" comment="Red Hat Enterprise Linux 6 Server is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734003" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734003"  version="501" comment="Red Hat Enterprise Linux 6 Workstation is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734003" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734004"  version="501" comment="Red Hat Enterprise Linux 6 ComputeNode is installed" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734003" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734005"  version="501" comment="java-1.6.0-sun is earlier than 1:1.6.0.33-1jpp.1.el6_2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734004" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734006"  version="501" comment="java-1.6.0-sun is signed with Red Hat redhatrelease2 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734001" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734007"  version="501" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.33-1jpp.1.el6_2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734004" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734008"  version="501" comment="java-1.6.0-sun-devel is signed with Red Hat redhatrelease2 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734001" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734009"  version="501" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.33-1jpp.1.el6_2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734004" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734010"  version="501" comment="java-1.6.0-sun-plugin is signed with Red Hat redhatrelease2 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734001" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734011"  version="501" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.33-1jpp.1.el6_2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734004" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734012"  version="501" comment="java-1.6.0-sun-demo is signed with Red Hat redhatrelease2 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734001" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734013"  version="501" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.33-1jpp.1.el6_2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734004" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734014"  version="501" comment="java-1.6.0-sun-src is signed with Red Hat redhatrelease2 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734001" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734015"  version="501" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.33-1jpp.1.el6_2" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734004" />
</rpminfo_test>
<rpminfo_test id="oval:com.redhat.rhsa:tst:20120734016"  version="501" comment="java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease2 key" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <object object_ref="oval:com.redhat.rhsa:obj:20120734010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20120734001" />
</rpminfo_test>

  </tests>

  <objects>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo objects   ~~~~~~~~~~~~~~~~~~~~ -->
    <rpminfo_object id="oval:com.redhat.rhsa:obj:20120734001"  version="501" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release-server</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20120734008"  version="501" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>java-1.6.0-sun-demo</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20120734003"  version="501" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release-workstation</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20120734004"  version="501" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release-computenode</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20120734002"  version="501" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>redhat-release-client</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20120734010"  version="501" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>java-1.6.0-sun-jdbc</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20120734009"  version="501" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>java-1.6.0-sun-src</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20120734005"  version="501" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>java-1.6.0-sun</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20120734007"  version="501" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>java-1.6.0-sun-plugin</name>
</rpminfo_object>
<rpminfo_object id="oval:com.redhat.rhsa:obj:20120734006"  version="501" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <name>java-1.6.0-sun-devel</name>
</rpminfo_object>

  </objects>
  <states>
    <!-- ~~~~~~~~~~~~~~~~~~~~   rpminfo states   ~~~~~~~~~~~~~~~~~~~~~ -->
    <rpminfo_state id="oval:com.redhat.rhsa:ste:20120734001"  version="501" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <signature_keyid  operation="equals">199e2f91fd431d51</signature_keyid>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20120734002"  version="501" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <signature_keyid  operation="equals">5326810137017186</signature_keyid>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20120734003"  version="501" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <version  operation="pattern match">^6[^[:digit:]]</version>
</rpminfo_state>
<rpminfo_state id="oval:com.redhat.rhsa:ste:20120734004"  version="501" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
  <evr datatype="evr_string" operation="less than">1:1.6.0.33-1jpp.1.el6_2</evr>
</rpminfo_state>

  </states>
</oval_definitions>

