<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="574223d1ffcde352dd063081d2f81f3e"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="slesp1-java-1_4_2-sun-5131"
    timestamp="1206626271"
    engine="1.0">
  <yum:name>slesp1-java-1_4_2-sun</yum:name>
  <summary lang="en">Security update for Sun Java</summary>
  <summary lang="de">Security update for Sun Java</summary>
  <description lang="en">Sun Java was updated to 1.4.2u17 to fix following security
vulnerabilities:

- CVE-2008-1158: Unspecified vulnerability in the Virtual
  Machine for Sun Java Runtime Environment (JRE) and JDK 6
  Update 4 and earlier, 5.0 Update 14 and earlier, and
  SDK/JRE 1.4.2_16 and earlier allows remote attackers
  should gain privileges via an untrusted application or
  applet, a different issue than CVE-2008-1186.
- CVE-2008-1186: Unspecified vulnerability in the Virtual
  Machine for Sun Java Runtime Environment (JRE) and JDK
  5.0 Update 13 and earlier, and SDK/JRE 1.4.2_16 and
  earlier, allows remote attackers to gain privileges via
  an untrusted application or applet, a different issue
  than CVE-2008-1185.
- CVE-2008-1187: Unspecified vulnerability in Sun Java
  Runtime Environment (JRE) and JDK 6 Update 4 and earlier,
  5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and
  earlier allows remote attackers to cause a denial of
  service (JRE crash) and possibly execute arbitrary code
  via unknown vectors related to XSLT transforms.
- CVE-2008-1189: Buffer overflow in Java Web Start in Sun
  JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and
  earlier, and SDK/JRE 1.4.2_16 and earlier allows remote
  attackers to execute arbitrary code via unknown vectors,
  a different issue than CVE-2008-1188.
- CVE-2008-1190: Unspecified vulnerability in Java Web
  Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0
  Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier
  allows remote attackers to gain privileges via an
  untrusted application, a different issue than
  CVE-2008-1191.
- CVE-2008-1192: Unspecified vulnerability in the Java
  Plug-in for Sun JDK and JRE 6 Update 4 and earlier, and
  5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and
  earlier, and 1.3.1_21 and earlier; allows remote
  attackers to bypass the same origin policy and &quot;execute
  local applications&quot; via unknown vectors.
- CVE-2008-1195: Unspecified vulnerability in Sun JDK and
  Java Runtime Environment (JRE) 6 Update 4 and earlier and
  5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and
  earlier; allows remote attackers to access arbitrary
  network services on the local host via unspecified
  vectors related to JavaScript and Java APIs.
- CVE-2008-1196: Stack-based buffer overflow in Java Web
  Start (javaws.exe) in Sun JDK and JRE 6 Update 4 and
  earlier and 5.0 Update 14 and earlier; and SDK and JRE
  1.4.2_16 and earlier; allows remote attackers to execute
  arbitrary code via a crafted JNLP file.
</description>
  <description lang="de">Sun Java was updated to 1.4.2u17 to fix following security
vulnerabilities:

- CVE-2008-1158: Unspecified vulnerability in the Virtual
  Machine for Sun Java Runtime Environment (JRE) and JDK 6
  Update 4 and earlier, 5.0 Update 14 and earlier, and
  SDK/JRE 1.4.2_16 and earlier allows remote attackers
  should gain privileges via an untrusted application or
  applet, a different issue than CVE-2008-1186.
- CVE-2008-1186: Unspecified vulnerability in the Virtual
  Machine for Sun Java Runtime Environment (JRE) and JDK
  5.0 Update 13 and earlier, and SDK/JRE 1.4.2_16 and
  earlier, allows remote attackers to gain privileges via
  an untrusted application or applet, a different issue
  than CVE-2008-1185.
- CVE-2008-1187: Unspecified vulnerability in Sun Java
  Runtime Environment (JRE) and JDK 6 Update 4 and earlier,
  5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and
  earlier allows remote attackers to cause a denial of
  service (JRE crash) and possibly execute arbitrary code
  via unknown vectors related to XSLT transforms.
- CVE-2008-1189: Buffer overflow in Java Web Start in Sun
  JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and
  earlier, and SDK/JRE 1.4.2_16 and earlier allows remote
  attackers to execute arbitrary code via unknown vectors,
  a different issue than CVE-2008-1188.
- CVE-2008-1190: Unspecified vulnerability in Java Web
  Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0
  Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier
  allows remote attackers to gain privileges via an
  untrusted application, a different issue than
  CVE-2008-1191.
- CVE-2008-1192: Unspecified vulnerability in the Java
  Plug-in for Sun JDK and JRE 6 Update 4 and earlier, and
  5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and
  earlier, and 1.3.1_21 and earlier; allows remote
  attackers to bypass the same origin policy and &quot;execute
  local applications&quot; via unknown vectors.
- CVE-2008-1195: Unspecified vulnerability in Sun JDK and
  Java Runtime Environment (JRE) 6 Update 4 and earlier and
  5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and
  earlier; allows remote attackers to access arbitrary
  network services on the local host via unspecified
  vectors related to JavaScript and Java APIs.
- CVE-2008-1196: Stack-based buffer overflow in Java Web
  Start (javaws.exe) in Sun JDK and JRE 6 Update 4 and
  earlier and 5.0 Update 14 and earlier; and SDK and JRE
  1.4.2_16 and earlier; allows remote attackers to execute
  arbitrary code via a crafted JNLP file.
</description>
  <yum:version ver="5131" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="java-1_4_2-sun" epoch="0" ver="1.4.2.17" rel="0.2" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-alsa" epoch="0" ver="1.4.2.17" rel="0.2" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-devel" epoch="0" ver="1.4.2.17" rel="0.2" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-jdbc" epoch="0" ver="1.4.2.17" rel="0.2" flags="EQ"/>
    <rpm:entry kind="atom" name="java-1_4_2-sun-plugin" epoch="0" ver="1.4.2.17" rel="0.2" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2.17" rel="0.2"/>
      <checksum type="sha" pkgid="YES">eadf251e3e72f4617371734cd1ee34695eae9d7f</checksum>
      <time file="1206701863" build="1206626271"/>
      <size package="18783514" installed="60032793" archive="60158292"/>
      <location xml:base="media://#1" href="suse/i586/java-1_4_2-sun-1.4.2.17-0.2.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun" epoch="0" ver="1.4.2.17" rel="0.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-alsa</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2.17" rel="0.2"/>
      <checksum type="sha" pkgid="YES">9d4f705fea32f675b4f5e6d590348f462d239091</checksum>
      <time file="1206701863" build="1206626271"/>
      <size package="24826" installed="26584" archive="26888"/>
      <location xml:base="media://#1" href="suse/i586/java-1_4_2-sun-alsa-1.4.2.17-0.2.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-alsa" epoch="0" ver="1.4.2.17" rel="0.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-alsa"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2.17" rel="0.2"/>
      <checksum type="sha" pkgid="YES">45e46c138aba3e10c4d1fbcc0af18da6e2abf30a</checksum>
      <time file="1206701863" build="1206626271"/>
      <size package="2915806" installed="8029135" archive="8039544"/>
      <location xml:base="media://#1" href="suse/i586/java-1_4_2-sun-devel-1.4.2.17-0.2.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-devel" epoch="0" ver="1.4.2.17" rel="0.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-jdbc</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2.17" rel="0.2"/>
      <checksum type="sha" pkgid="YES">ea1dec98901846e74a75ba30b5e925342b8ce1fc</checksum>
      <time file="1206701863" build="1206626271"/>
      <size package="27086" installed="50016" archive="50316"/>
      <location xml:base="media://#1" href="suse/i586/java-1_4_2-sun-jdbc-1.4.2.17-0.2.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-jdbc" epoch="0" ver="1.4.2.17" rel="0.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-jdbc"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>java-1_4_2-sun-plugin</name>
      <arch>i586</arch>
      <version epoch="0" ver="1.4.2.17" rel="0.2"/>
      <checksum type="sha" pkgid="YES">557ab7cd1b47e606672112650ff5993926d8d5d6</checksum>
      <time file="1206701864" build="1206626271"/>
      <size package="803412" installed="2649051" archive="2654912"/>
      <location xml:base="media://#1" href="suse/i586/java-1_4_2-sun-plugin-1.4.2.17-0.2.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="java-1_4_2-sun-plugin" epoch="0" ver="1.4.2.17" rel="0.2" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="java-1_4_2-sun-plugin"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
