<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="ae79482178b54b4ffd641e1254a018da"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sledp2-java-1_5_0-ibm-5591"
    timestamp="1221126912"
    engine="1.0">
  <yum:name>sledp2-java-1_5_0-ibm</yum:name>
  <summary lang="en">Security update for IBM Java 1.5</summary>
  <summary lang="de">Security update for IBM Java 1.5</summary>
  <description lang="en">IBM Java 5 was updated to SR8 to fix various security
issues:

CVE-2008-3104: Multiple vulnerabilities with unsigned
applets were reported. A remote attacker could misuse an
unsigned applet to connect to localhost services running on
the host running the applet.

CVE-2008-3106: A vulnerability in the XML processing API
was found. A remote attacker who caused malicious XML to be
processed by an untrusted applet or application was able to
elevate permissions to access URLs on a remote host.

CVE-2008-3108: A buffer overflow vulnerability was found in
the font processing code. This allowed remote attackers to
extend the permissions of an untrusted applet or
application, allowing it to read and/or write local files,
as well as to execute local applications accessible to the
user running the untrusted application.

CVE-2008-3111: Several buffer overflow vulnerabilities in
Java Web Start were reported.  These vulnerabilities
allowed an untrusted Java Web Start application to elevate
its privileges, allowing it to read and/or write local
files, as well as to execute local applications accessible
to the user running the untrusted application.

CVE-2008-3112, CVE-2008-3113: Two file processing
vulnerabilities in Java Web Start were found. A remote
attacker, by means of an untrusted Java Web Start
application, was able to create or delete arbitrary files
with the permissions of the user running the untrusted
application.

CVE-2008-3114: A vulnerability in Java Web Start when
processing untrusted applications was reported. An attacker
was able to acquire sensitive information, such as the
cache location.

This release also reinstates previous Crypto Export policy
jars lost between SR3 and SR8.
</description>
  <description lang="de">IBM Java 5 was updated to SR8 to fix various security
issues:

CVE-2008-3104: Multiple vulnerabilities with unsigned
applets were reported. A remote attacker could misuse an
unsigned applet to connect to localhost services running on
the host running the applet.

CVE-2008-3106: A vulnerability in the XML processing API
was found. A remote attacker who caused malicious XML to be
processed by an untrusted applet or application was able to
elevate permissions to access URLs on a remote host.

CVE-2008-3108: A buffer overflow vulnerability was found in
the font processing code. This allowed remote attackers to
extend the permissions of an untrusted applet or
application, allowing it to read and/or write local files,
as well as to execute local applications accessible to the
user running the untrusted application.

CVE-2008-3111: Several buffer overflow vulnerabilities in
Java Web Start were reported.  These vulnerabilities
allowed an untrusted Java Web Start application to elevate
its privileges, allowing it to read and/or write local
files, as well as to execute local applications accessible
to the user running the untrusted application.

CVE-2008-3112, CVE-2008-3113: Two file processing
vulnerabilities in Java Web Start were found. A remote
attacker, by means of an untrusted Java Web Start
application, was able to create or delete arbitrary files
with the permissions of the user running the untrusted
application.

CVE-2008-3114: A vulnerability in Java Web Start when
processing untrusted applications was reported. An attacker
was able to acquire sensitive information, such as the
cache location.

This release also reinstates previous Crypto Export policy
jars lost between SR3 and SR8.
</description>
  <yum:version ver="5591" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="java-1_5_0-ibm" epoch="0" ver="1.5.0_sr8" rel="1.3" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-alsa" epoch="0" ver="1.5.0_sr8" rel="1.3" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-demo" epoch="0" ver="1.5.0_sr8" rel="1.3" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-devel" epoch="0" ver="1.5.0_sr8" rel="1.3" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-jdbc" epoch="0" ver="1.5.0_sr8" rel="1.3" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-plugin" epoch="0" ver="1.5.0_sr8" rel="1.3" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_5_0-ibm-src" epoch="0" ver="1.5.0_sr8" rel="1.3" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.3"/>
      <checksum type="sha" pkgid="YES">52f9df4c426ea2a15b050f47e2790146101a6100</checksum>
      <time file="1221148005" build="1221126912"/>
      <size package="46280082" installed="66363364" archive="66417396"/>
      <location xml:base="media://#1" href="suse/i586/java-1_5_0-ibm-1.5.0_sr10-0.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm" epoch="0" ver="1.5.0_sr8" rel="1.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-alsa</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.3"/>
      <checksum type="sha" pkgid="YES">992b8d2594bb69729da256452e9bb6e8036882ac</checksum>
      <time file="1221148006" build="1221126912"/>
      <size package="46759" installed="95662" archive="95964"/>
      <location xml:base="media://#1" href="suse/i586/java-1_5_0-ibm-alsa-1.5.0_sr10-0.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-alsa" epoch="0" ver="1.5.0_sr8" rel="1.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-alsa"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-demo</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.3"/>
      <checksum type="sha" pkgid="YES">2a02ea5a9a603d9a1bc01548530af70b1296e70f</checksum>
      <time file="1221148006" build="1221126912"/>
      <size package="3448005" installed="6500063" archive="6615120"/>
      <location xml:base="media://#1" href="suse/i586/java-1_5_0-ibm-demo-1.5.0_sr10-0.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-demo" epoch="0" ver="1.5.0_sr8" rel="1.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-demo"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.3"/>
      <checksum type="sha" pkgid="YES">89d18c47be6f2cb33240f85c0a813579e702bd9c</checksum>
      <time file="1221148006" build="1221126912"/>
      <size package="9046239" installed="13590950" archive="13613496"/>
      <location xml:base="media://#1" href="suse/i586/java-1_5_0-ibm-devel-1.5.0_sr10-0.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-devel" epoch="0" ver="1.5.0_sr8" rel="1.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-jdbc</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.3"/>
      <checksum type="sha" pkgid="YES">281bcf714ad6238cedf05f14a496ff69e2fe4405</checksum>
      <time file="1221148006" build="1221126912"/>
      <size package="32066" installed="70795" archive="71092"/>
      <location xml:base="media://#1" href="suse/i586/java-1_5_0-ibm-jdbc-1.5.0_sr10-0.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-jdbc" epoch="0" ver="1.5.0_sr8" rel="1.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-jdbc"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-plugin</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.3"/>
      <checksum type="sha" pkgid="YES">99710b0caf8246627365212ee569a18ed6c27b75</checksum>
      <time file="1221148006" build="1221126912"/>
      <size package="872884" installed="2500046" archive="1923676"/>
      <location xml:base="media://#1" href="suse/i586/java-1_5_0-ibm-plugin-1.5.0_sr10-0.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-plugin" epoch="0" ver="1.5.0_sr8" rel="1.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-plugin"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_5_0-ibm-src</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.5.0_sr8" rel="1.3"/>
      <checksum type="sha" pkgid="YES">509ec8740fd497002b77a54f5b7a67afb41fdc24</checksum>
      <time file="1221148007" build="1221126912"/>
      <size package="8150679" installed="8433075" archive="8433528"/>
      <location xml:base="media://#1" href="suse/i586/java-1_5_0-ibm-src-1.5.0_sr10-0.3.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_5_0-ibm-src" epoch="0" ver="1.5.0_sr8" rel="1.3" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_5_0-ibm-src"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
