-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 APPLE-SA-2009-12-03-2 Java for Mac OS X 10.5 Update 6
Java for Mac OS X 10.5 Update 6 is now available and addresses the following: Java CVE-ID: CVE-2009-3869, CVE-2009-3871, CVE-2009-3875, CVE-2009-3874, CVE-2009-3728, CVE-2009-3872, CVE-2009-3868, CVE-2009-3867, CVE-2009-3884, CVE-2009-3873, CVE-2009-3877, CVE-2009-3865, CVE-2009-3866 Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8 Impact: Multiple vulnerabilities in Java 1.6.0_15 Description: Multiple vulnerabilities exist in Java 1.6.0_15, the most serious of which may allow an untrusted Java applet to obtain elevated privileges. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues are addressed by updating to Java version 1.6.0_17. Further information is available via the Sun Java website at http://java.sun.com/javase/6/webnotes/ReleaseNotes.html Credit to Kevin Finisterre of Netragard for reporting CVE-2009-3867 to Apple. Java CVE-ID: CVE-2009-3869, CVE-2009-3871, CVE-2009-3875, CVE-2009-3874, CVE-2009-3728, CVE-2009-3872, CVE-2009-3868, CVE-2009-3867, CVE-2009-3884, CVE-2009-3873, CVE-2009-3877 Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8 Impact: Multiple vulnerabilities in Java 1.5.0_20 Description: Multiple vulnerabilities exist in Java 1.5.0_20, the most serious of which may allow an untrusted Java applet to obtain elevated privileges. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues are addressed by updating to Java version 1.5.0_22. Further information is available via the Sun Java website at http://java.sun.com/j2se/1.5.0/ReleaseNotes.html Java Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8 Impact: Multiple vulnerabilities in Java 1.4.2_22 Description: Multiple vulnerabilities exist in Java 1.4.2_22, the most serious of which may allow an untrusted Java applet to obtain elevated privileges. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues are addressed by disabling Java version 1.4.2. Java CVE-ID: CVE-2009-2843 Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8 Impact: An expired certificate for a Java applet is treated as valid Description: An expired certificate for a Java applet is treated as valid. This issue is addressed through improved handling of expired certificates. Credit to Simon Heimlicher of ETH Zurich for reporting this issue. Java for Mac OS X 10.5 Update 6 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads web site: http://www.apple.com/support/downloads/ The download file is named: JavaForMacOSX10.5Update6.dmg Its SHA-1 digest is: 04d4d028aa60f0a855c5393f81a6ea0d1af475bc Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.9 (Darwin) iQEcBAEBAgAGBQJLFwRMAAoJEHkodeiKZIkBlVMH/A78ZgscuYoa9hF7nnTO93+Q RfCcJahwB3cedyUBC/b1UWHck+e1Ul2FfueiOI/tJTmdEqzORjahdmx5Bqpa43nO hP00yGrDHNVk4b0B87wJwkq6fPGNaBZynGGOqFONvLUsTJQhlGMzI646SIECnP+k XlYAzF8itxDDqiJDl0AfCNt1sED7mfPGEIC5Aa2bB5mgF9TYZTHx5NysAhK0qxS8 1dtFxKBS/B4mY6UZKAADRzSU8eAO0S7nN5re5MmnDPIfvLzOAWfuVyP1giMR4sT7 qZQbj6U3TXTDJQ7q25lQUfBl2V5bTWosKPdEveKWReO/i4HpleMkrBDWkYd6PYg= =234P -----END PGP SIGNATURE----- *********************************** * POST TO MEDIANEWS@ETSKYWARN.NET * *********************************** Medianews mailing list Medianews@etskywarn.net http://lists.etskywarn.net/mailman/listinfo/medianews