===================================================================== CERT-Renater Note d'Information No. 2009/VULN501 _____________________________________________________________________ DATE : 04/12/2009 HARDWARE PLATFORM(S) : / OPERATING SYSTEM(S) : Mac OS X 10.6, Mac OS X 10.5 running Java. ====================================================================== http://support.apple.com/kb/HT3969 http://support.apple.com/kb/HT3970 ______________________________________________________________________ APPLE-SA-2009-12-03-1 Java for Mac OS X 10.6 Update 1 Java for Mac OS X 10.6 Update 1 is now available and addresses the following: Java CVE-ID: CVE-2009-3869, CVE-2009-3871, CVE-2009-3875, CVE-2009-3874, CVE-2009-3728, CVE-2009-3872, CVE-2009-3868, CVE-2009-3867, CVE-2009-3884, CVE-2009-3873, CVE-2009-3877, CVE-2009-3865, CVE-2009-3866 Available for: Mac OS X v10.6.2 and later, Mac OS X Server v10.6.2 and later Impact: Multiple vulnerabilities in Java 1.6.0_15 Description: Multiple vulnerabilities exist in Java 1.6.0_15, the most serious of which may allow an untrusted Java applet to obtain elevated privileges. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues are addressed by updating to Java version 1.6.0_17. Further information is available via the Sun Java website at http://java.sun.com/javase/6/webnotes/ReleaseNotes.html Credit to Kevin Finisterre of Netragard for reporting CVE-2009-3867 to Apple. Java CVE-ID: CVE-2009-2843 Available for: Mac OS X v10.6.2 and later, Mac OS X Server v10.6.2 and later Impact: An expired certificate for a Java applet is treated as valid Description: An expired certificate for a Java applet is treated as valid. This issue is addressed through improved handling of expired certificates. Credit to Simon Heimlicher of ETH Zurich for reporting this issue. Java for Mac OS X 10.6 Update 1 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads web site: http://www.apple.com/support/downloads/ The download file is named: JavaForMacOSX10.6Update1.dmg Its SHA-1 digest is: e31791c61b56c7db104baffb00971fad88feb8e4 Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ _____________________________________________________________________ APPLE-SA-2009-12-03-2 Java for Mac OS X 10.5 Update 6 Java for Mac OS X 10.5 Update 6 is now available and addresses the following: Java CVE-ID: CVE-2009-3869, CVE-2009-3871, CVE-2009-3875, CVE-2009-3874, CVE-2009-3728, CVE-2009-3872, CVE-2009-3868, CVE-2009-3867, CVE-2009-3884, CVE-2009-3873, CVE-2009-3877, CVE-2009-3865, CVE-2009-3866 Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8 Impact: Multiple vulnerabilities in Java 1.6.0_15 Description: Multiple vulnerabilities exist in Java 1.6.0_15, the most serious of which may allow an untrusted Java applet to obtain elevated privileges. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues are addressed by updating to Java version 1.6.0_17. Further information is available via the Sun Java website at http://java.sun.com/javase/6/webnotes/ReleaseNotes.html Credit to Kevin Finisterre of Netragard for reporting CVE-2009-3867 to Apple. Java CVE-ID: CVE-2009-3869, CVE-2009-3871, CVE-2009-3875, CVE-2009-3874, CVE-2009-3728, CVE-2009-3872, CVE-2009-3868, CVE-2009-3867, CVE-2009-3884, CVE-2009-3873, CVE-2009-3877 Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8 Impact: Multiple vulnerabilities in Java 1.5.0_20 Description: Multiple vulnerabilities exist in Java 1.5.0_20, the most serious of which may allow an untrusted Java applet to obtain elevated privileges. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues are addressed by updating to Java version 1.5.0_22. Further information is available via the Sun Java website at http://java.sun.com/j2se/1.5.0/ReleaseNotes.html Java Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8 Impact: Multiple vulnerabilities in Java 1.4.2_22 Description: Multiple vulnerabilities exist in Java 1.4.2_22, the most serious of which may allow an untrusted Java applet to obtain elevated privileges. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues are addressed by disabling Java version 1.4.2. Java CVE-ID: CVE-2009-2843 Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8 Impact: An expired certificate for a Java applet is treated as valid Description: An expired certificate for a Java applet is treated as valid. This issue is addressed through improved handling of expired certificates. Credit to Simon Heimlicher of ETH Zurich for reporting this issue. Java for Mac OS X 10.5 Update 6 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads web site: http://www.apple.com/support/downloads/ The download file is named: JavaForMacOSX10.5Update6.dmg Its SHA-1 digest is: 04d4d028aa60f0a855c5393f81a6ea0d1af475bc Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ ====================================================================== ========================================================= Les serveurs de référence du CERT-Renater http://www.urec.fr/securite http://www.cru.fr/securite http://www.renater.fr ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 151 bd de l'Hopital | fax : 01-53-94-20-41 + + 75013 Paris | email: certsvp@renater.fr + =========================================================