<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="b7dba13e62e15fbfd53891981a35bb05"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sledp2-java-1_5_0-ibm-5557"
    timestamp="1219760552"
    engine="1.0">
  <yum:name>sledp2-java-1_5_0-ibm</yum:name>
  <summary lang="en">Security update for IBM Java 1.5.0</summary>
  <summary lang="de">Security update for IBM Java 1.5.0</summary>
  <description lang="en">IBM Java 5 was updated to SR8 to fix various security
issues:

CVE-2008-3104: Multiple vulnerabilities with unsigned
applets were reported. A remote attacker could misuse an
unsigned applet to connect to localhost services running on
the host running the applet.

CVE-2008-3106: A vulnerability in the XML processing API
was found. A remote attacker who caused malicious XML to be
processed by an untrusted applet or application was able to
elevate permissions to access URLs on a remote host.

CVE-2008-3108: A buffer overflow vulnerability was found in
the font processing code. This allowed remote attackers to
extend the permissions of an untrusted applet or
application, allowing it to read and/or write local files,
as well as to execute local applications accessible to the
user running the untrusted application.

CVE-2008-3111: Several buffer overflow vulnerabilities in
Java Web Start were reported.  These vulnerabilities
allowed an untrusted Java Web Start application to elevate
its privileges, allowing it to read and/or write local
files, as well as to execute local applications accessible
to the user running the untrusted application.

CVE-2008-3112, CVE-2008-3113: Two file processing
vulnerabilities in Java Web Start were found. A remote
attacker, by means of an untrusted Java Web Start
application, was able to create or delete arbitrary files
with the permissions of the user running the untrusted
application.

CVE-2008-3114: A vulnerability in Java Web Start when
processing untrusted applications was reported. An attacker
was able to acquire sensitive information, such as the
cache location.
</description>
  <description lang="de">IBM Java 5 was updated to SR8 to fix various security
issues:

CVE-2008-3104: Multiple vulnerabilities with unsigned
applets were reported. A remote attacker could misuse an
unsigned applet to connect to localhost services running on
the host running the applet.

CVE-2008-3106: A vulnerability in the XML processing API
was found. A remote attacker who caused malicious XML to be
processed by an untrusted applet or application was able to
elevate permissions to access URLs on a remote host.

CVE-2008-3108: A buffer overflow vulnerability was found in
the font processing code. This allowed remote attackers to
extend the permissions of an untrusted applet or
application, allowing it to read and/or write local files,
as well as to execute local applications accessible to the
user running the untrusted application.

CVE-2008-3111: Several buffer overflow vulnerabilities in
Java Web Start were reported.  These vulnerabilities
allowed an untrusted Java Web Start application to elevate
its privileges, allowing it to read and/or write local
files, as well as to execute local applications accessible
to the user running the untrusted application.

CVE-2008-3112, CVE-2008-3113: Two file processing
vulnerabilities in Java Web Start were found. A remote
attacker, by means of an untrusted Java Web Start
application, was able to create or delete arbitrary files
with the permissions of the user running the untrusted
application.

CVE-2008-3114: A vulnerability in Java Web Start when
processing untrusted applications was reported. An attacker
was able to acquire sensitive information, such as the
cache location.
</description>
  <yum:version ver="5557" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="java-1_5_0-ibm" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-alsa" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-demo" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-devel" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-jdbc" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-plugin" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-src" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.1"/>
      <checksum type="sha" pkgid="YES">facafb09a789b091a0550816761b19445703ddc7</checksum>
      <time file="1219798300" build="1219760552"/>
      <size package="46277233" installed="66360334" archive="66414364"/>
      <location xml:base="media://#1" href="suse/i586/java-1_5_0-ibm-1.5.0_sr10-0.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-alsa</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.1"/>
      <checksum type="sha" pkgid="YES">f68f376586822d70c8fbaeb92288e568b1643392</checksum>
      <time file="1219798301" build="1219760552"/>
      <size package="46679" installed="95662" archive="95964"/>
      <location xml:base="media://#1" href="suse/i586/java-1_5_0-ibm-alsa-1.5.0_sr10-0.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-alsa" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-alsa"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-demo</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.1"/>
      <checksum type="sha" pkgid="YES">9066ad3b2d0506f7fe1554bfd27172a4cdb64a89</checksum>
      <time file="1219798301" build="1219760552"/>
      <size package="3448213" installed="6500063" archive="6615120"/>
      <location xml:base="media://#1" href="suse/i586/java-1_5_0-ibm-demo-1.5.0_sr10-0.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-demo" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-demo"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.1"/>
      <checksum type="sha" pkgid="YES">54cbe2bec7d51dfa09114b8458c3bd077ea87646</checksum>
      <time file="1219798302" build="1219760552"/>
      <size package="9045919" installed="13590950" archive="13613496"/>
      <location xml:base="media://#1" href="suse/i586/java-1_5_0-ibm-devel-1.5.0_sr10-0.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-devel" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-jdbc</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.1"/>
      <checksum type="sha" pkgid="YES">4fab75e0c18884c77bc0f7810a479ccde714e2b4</checksum>
      <time file="1219798303" build="1219760552"/>
      <size package="31970" installed="70795" archive="71092"/>
      <location xml:base="media://#1" href="suse/i586/java-1_5_0-ibm-jdbc-1.5.0_sr10-0.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-jdbc" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-jdbc"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-plugin</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.1"/>
      <checksum type="sha" pkgid="YES">04e64db78a6b88cf4d81dfd08b3bbaea3cbfc316</checksum>
      <time file="1219798303" build="1219760552"/>
      <size package="872699" installed="2500046" archive="1923676"/>
      <location xml:base="media://#1" href="suse/i586/java-1_5_0-ibm-plugin-1.5.0_sr10-0.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-plugin" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-plugin"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-src</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.1"/>
      <checksum type="sha" pkgid="YES">03acacb0b9f1991c59b6eb416d6d9cac4e0551a7</checksum>
      <time file="1219798303" build="1219760552"/>
      <size package="8150266" installed="8433075" archive="8433528"/>
      <location xml:base="media://#1" href="suse/i586/java-1_5_0-ibm-src-1.5.0_sr10-0.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-src" epoch="0" ver="1.5.0_sr8" rel="1.1" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-src"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
