-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2012.0846
        Java for OS X 2012-005 and Java for Mac OS X 10.6 Update 10
                             6 September 2012

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:          Java for OS X
Publisher:        Apple
Operating System: Mac OS X
Impact/Access:    Reduced Security -- Remote/Unauthenticated
Resolution:       Patch/Upgrade
CVE Names:        CVE-2012-0547  

Reference:        ASB-2012.0120

Comment: Related Bulletin
         http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.html

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

APPLE-SA-2012-09-05-1 Java for OS X 2012-005 and
Java for Mac OS X 10.6 Update 10

Java for OS X 2012-005 and Java for Mac OS X 10.6 Update 10 are now
available and address the following:

Java
Available for: Mac OS X v10.6.8, Mac OS X Server v10.6.8,
OS X Lion v10.7 or later, OS X Lion Server v10.7 or later,
OS X Mountain Lion 10.8 or later
Description:  An opportunity for security-in-depth hardening is
addressed by updating to Java version 1.6.0_35. Further information
is available via the Java website at
http://www.oracle.com/technetwork/topics/security/alert-
cve-2012-4681-1835715.html
CVE-ID
CVE-2012-0547

Java for OS X 2012-005 and Java for Mac OS X 10.6 Update 10
may be obtained from the Software Update pane in System Preferences,
or Apple's Software Downloads web site:
http://www.apple.com/support/downloads/

For Mac OS X v10.6 systems
The download file is named: JavaForMacOSX10.6.dmg
Its SHA-1 digest is: 6218979ae4eaef5ea7849cb4455e2c6f8bf362d2

For OS X Lion and Mountain Lion systems
The download file is named: JavaForOSX.dmg
Its SHA-1 digest is: e0750c72972b8a2ccbcb3144bb31d74419276387

Information will also be posted to the Apple Security Updates
web site: http://support.apple.com/kb/HT1222

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/

- -----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.17 (Darwin)
Comment: GPGTools - http://gpgtools.org

iQIcBAEBAgAGBQJQRoIGAAoJEPefwLHPlZEwqLIQAI/iwWUZRJ17R8WepzGdMtOC
7CfvG6Xm4sO56jEz5Idg8elpKaoDr5xzjyBO0PF/I+vM2DJo5X6Dm25r7TstWHVe
/Ucnan0yRbn6bqUgsKyAubQy+yENxJEr3ed/xe+EUcRvw8mX/kHH7Rq0boMtxx3D
eyq/t8Z4rY3B4BLS0RPG0sKNR2cNetE1yNKxHNskOAc3qsgv8oa7XgR9q+z3lHbS
t+BWp3dDF+gcTzdPJVzE1ksC4MCnPYYA6qoNVSj5o8AFU6ZJ5BGaQWIVY67qXZt4
yls0P4bV0LZbrVolrfzpysfgoACT8NutibJ9fWe8UjqN8t+0NvsWKMQIO/Yye4uF
aqWUB6P8uzaVEXksIuDuLtLLF0IhdWk7l9wcW9L4h/vgFvcwtT8o7fTn1av7zBhO
CP/sF3iM8n50b42m/dD+nkriIlreH7tWMo5C+GgEKaXSgG9YeqnzzCXf30P20wxF
oYfpwGgGKrVvojUbuPfZOUe8bpQNoCec8TNtXjZAuOYkE7Ku7RXPeB0Y1znINVNj
VXfQcsJlSEjkqS5TYofaNZ3Qk4hVUbexTwuHCMxevY0L1k7PId829wzoPoE70vSw
0BCYAHZzeCkfQpc+jElB8a3rXStYtAvc8OhI2Wq6bLHVclokFSk7YbmrEGDMGM/Z
vCB4qLe1cpGMcRIoYGdA
=v5mf
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBUEg80e4yVqjM2NGpAQKAWBAAnae641rtMhxKdySu1GJbAVbY/a8UB8gQ
jg2wDSPvhXDgaLedzI8e0nAHlCb1Si19Jvgl4SBk8LCjA7gmQZj4n/LkR69k3wqG
JGR+FHF8up9e4YERRO6FpjCdKkHvyN+a+JacNoXvugFP19MUSXYc63WLpJ6X1JQS
zoMmgf3/R8QfZ63gKTKnTAia2X1h+OiEe2J1+UpkqfxBfEf28Oy+Me5rTzXwCbbJ
inNx3Mm4Jy/QNqpfbFuITyXAsaBSOFYvlkIF7y6TOFnF6lTzZCzcRnnXKVrsTTtC
4ogl6/dSqqCvvNWvxbQC0v3+i/msB68HcGaweHWsnxijtyCxVq4LxTn4YlJLxr6T
xrR0MOz7oIzR/ahdUDDfnLGE6CiU3JgtV9AR6/Nv6O+vzeAmFbDjsONtqdtNfcxK
ZUarFZhgEeSx+IsgctGhLZP0atruT0YsOUTDan80U7ppf9hat/kTQFI1lJTcZQ9R
1B9tSb6X1trRmmCPMY+UgtMS/fZA56h0aCUC6dEZ7w1+i+4j+sgTTjF8m5vIscpG
cvO0qHYXsMmVXXl+6RlSrQm/onyda3HbUl7p2v5mM06JmehxBoit7ZKoyJq8937P
gBtESlFag+Ezro77c/XFIdCOoBYT/N0/gZd2HqasWta+aHET4o1CInk0oy/lvtId
QJ4nagX6Vec=
=I4sj
-----END PGP SIGNATURE-----