Date: Tue, 4 May 2010 14:09:36 -0500 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Critical: java (jdk 1.6.0) on SL4.x, SL5.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Critical: java (jdk 1.6.0) security update Issue date: 2010-04-19 CVE Names: CVE-2010-0886 CVE-2010-0887 This update fixes two vulnerabilities in the Sun Java 6 Runtime Environment and the Sun Java 6 Software Development Kit. Further information about these flaws can be found on the Oracle Security Alert page listed in the References section. (CVE-2010-0886, CVE-2010-0887) All running instances of Sun Java must be restarted for the update to take effect. NOTE: jdk-1.6.0_20-fcs.x86_64.rpm has not been signed. We cannot sign this package without breaking it. SL 4.x SRPMS: java-1.6.0-sun-compat-1.6.0.20-1.sl4.jpp.src.rpm i386: x86_64: SL 5.x SRPMS: java-1.6.0-sun-compat-1.6.0.20-1.sl5.jpp.src.rpm i386: java-1.6.0-sun-compat-1.6.0.20-1.sl5.jpp.i586.rpm jdk-1.6.0_20-fcs.i586.rpm x86_64: java-1.6.0-sun-compat-1.6.0.20-1.sl5.jpp.i586.rpm java-1.6.0-sun-compat-1.6.0.20-1.sl5.jpp.x86_64.rpm jdk-1.6.0_20-fcs.i586.rpm jdk-1.6.0_20-fcs.x86_64.rpm -Connie Sieh -Troy Dawson