<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="b7dba13e62e15fbfd53891981a35bb05"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sledp2-java-1_5_0-ibm-5557"
    timestamp="1219760544"
    engine="1.0">
  <yum:name>sledp2-java-1_5_0-ibm</yum:name>
  <summary lang="en">Security update for IBM Java 1.5.0</summary>
  <summary lang="de">Security update for IBM Java 1.5.0</summary>
  <description lang="en">IBM Java 5 was updated to SR8 to fix various security
issues:

CVE-2008-3104: Multiple vulnerabilities with unsigned
applets were reported. A remote attacker could misuse an
unsigned applet to connect to localhost services running on
the host running the applet.

CVE-2008-3106: A vulnerability in the XML processing API
was found. A remote attacker who caused malicious XML to be
processed by an untrusted applet or application was able to
elevate permissions to access URLs on a remote host.

CVE-2008-3108: A buffer overflow vulnerability was found in
the font processing code. This allowed remote attackers to
extend the permissions of an untrusted applet or
application, allowing it to read and/or write local files,
as well as to execute local applications accessible to the
user running the untrusted application.

CVE-2008-3111: Several buffer overflow vulnerabilities in
Java Web Start were reported.  These vulnerabilities
allowed an untrusted Java Web Start application to elevate
its privileges, allowing it to read and/or write local
files, as well as to execute local applications accessible
to the user running the untrusted application.

CVE-2008-3112, CVE-2008-3113: Two file processing
vulnerabilities in Java Web Start were found. A remote
attacker, by means of an untrusted Java Web Start
application, was able to create or delete arbitrary files
with the permissions of the user running the untrusted
application.

CVE-2008-3114: A vulnerability in Java Web Start when
processing untrusted applications was reported. An attacker
was able to acquire sensitive information, such as the
cache location.
</description>
  <description lang="de">IBM Java 5 was updated to SR8 to fix various security
issues:

CVE-2008-3104: Multiple vulnerabilities with unsigned
applets were reported. A remote attacker could misuse an
unsigned applet to connect to localhost services running on
the host running the applet.

CVE-2008-3106: A vulnerability in the XML processing API
was found. A remote attacker who caused malicious XML to be
processed by an untrusted applet or application was able to
elevate permissions to access URLs on a remote host.

CVE-2008-3108: A buffer overflow vulnerability was found in
the font processing code. This allowed remote attackers to
extend the permissions of an untrusted applet or
application, allowing it to read and/or write local files,
as well as to execute local applications accessible to the
user running the untrusted application.

CVE-2008-3111: Several buffer overflow vulnerabilities in
Java Web Start were reported.  These vulnerabilities
allowed an untrusted Java Web Start application to elevate
its privileges, allowing it to read and/or write local
files, as well as to execute local applications accessible
to the user running the untrusted application.

CVE-2008-3112, CVE-2008-3113: Two file processing
vulnerabilities in Java Web Start were found. A remote
attacker, by means of an untrusted Java Web Start
application, was able to create or delete arbitrary files
with the permissions of the user running the untrusted
application.

CVE-2008-3114: A vulnerability in Java Web Start when
processing untrusted applications was reported. An attacker
was able to acquire sensitive information, such as the
cache location.
</description>
  <yum:version ver="5557" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="java-1_5_0-ibm" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-32bit" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-alsa-32bit" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-demo" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-devel" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-devel-32bit" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-src" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.1"/>
      <checksum type="sha" pkgid="YES">8664f3aee2755705d3bb5fa4abb5202fd52f03b3</checksum>
      <time file="1219798236" build="1219760544"/>
      <size package="48781899" installed="73772524" archive="73820112"/>
      <location xml:base="media://#1" href="suse/x86_64/java-1_5_0-ibm-1.5.0_sr10-0.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-32bit</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.1"/>
      <checksum type="sha" pkgid="YES">7eda3de1de4109c8e5870b439edcb6ed0beaacc2</checksum>
      <time file="1219798301" build="1219760661"/>
      <size package="46268820" installed="66351411" archive="66404832"/>
      <location xml:base="media://#1" href="suse/x86_64/java-1_5_0-ibm-32bit-1.5.0_sr10-0.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-32bit" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-32bit"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-alsa-32bit</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.1"/>
      <checksum type="sha" pkgid="YES">595d8c2a8226dc628d0b3f1bfdd6b54fbb6ea831</checksum>
      <time file="1219798301" build="1219760686"/>
      <size package="46982" installed="95662" archive="96556"/>
      <location xml:base="media://#1" href="suse/x86_64/java-1_5_0-ibm-alsa-32bit-1.5.0_sr10-0.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-alsa-32bit" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-alsa-32bit"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-demo</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.1"/>
      <checksum type="sha" pkgid="YES">0fabdae9de12783c20e9cd8d57d7cbcedc68f392</checksum>
      <time file="1219798236" build="1219760544"/>
      <size package="3447975" installed="6500063" archive="6615120"/>
      <location xml:base="media://#1" href="suse/x86_64/java-1_5_0-ibm-demo-1.5.0_sr10-0.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-demo" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-demo"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-devel</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.1"/>
      <checksum type="sha" pkgid="YES">a34e95ac1483753abd98f02e9fc1d128cbb95184</checksum>
      <time file="1219798237" build="1219760544"/>
      <size package="8495059" installed="12930129" archive="12951456"/>
      <location xml:base="media://#1" href="suse/x86_64/java-1_5_0-ibm-devel-1.5.0_sr10-0.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-devel" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-devel-32bit</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.1"/>
      <checksum type="sha" pkgid="YES">ea19b895108e44cbe14c816da21a7447a4318a0d</checksum>
      <time file="1219798302" build="1219760689"/>
      <size package="9044946" installed="13588702" archive="13611504"/>
      <location xml:base="media://#1" href="suse/x86_64/java-1_5_0-ibm-devel-32bit-1.5.0_sr10-0.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-devel-32bit" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-devel-32bit"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-src</name>
      <arch>x86_64</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.1"/>
      <checksum type="sha" pkgid="YES">5e6eb90e6881607bda32fae3b9723ca691480362</checksum>
      <time file="1219798237" build="1219760544"/>
      <size package="8150827" installed="8433075" archive="8433528"/>
      <location xml:base="media://#1" href="suse/x86_64/java-1_5_0-ibm-src-1.5.0_sr10-0.3.x86_64.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-src" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-src"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
