LWN.net Logo

java-1.6.0-openjdk: multiple vulnerabilities

Package(s):java-1.6.0-openjdk CVE #(s):CVE-2008-5350 CVE-2008-5349 CVE-2008-5347 CVE-2008-5348 CVE-2008-5360 CVE-2008-5359 CVE-2008-5351 CVE-2008-5356 CVE-2008-5352 CVE-2008-5358 CVE-2008-5353 CVE-2008-5354 CVE-2008-5357
Created:December 8, 2008 Updated:November 18, 2009
Description:

From the Fedora advisory:

[ 1 ] Bug #472201 - CVE-2008-5350 OpenJDK allows to list files within the user home directory (6484091) https://bugzilla.redhat.com/show_bug.cgi?id=472201
[ 2 ] Bug #472206 - CVE-2008-5349 OpenJDK RSA public key length denial-of-service (6497740) https://bugzilla.redhat.com/show_bug.cgi?id=472206
[ 3 ] Bug #472208 - CVE-2008-5347 OpenJDK applet privilege escalation via JAX package access (6592792) https://bugzilla.redhat.com/show_bug.cgi?id=472208
[ 4 ] Bug #472209 - CVE-2008-5348 OpenJDK Denial-Of-Service in kerberos authentication (6588160) https://bugzilla.redhat.com/show_bug.cgi?id=472209
[ 5 ] Bug #472211 - CVE-2008-5360 OpenJDK temporary files have guessable file names (6721753) https://bugzilla.redhat.com/show_bug.cgi?id=472211
[ 6 ] Bug #472212 - CVE-2008-5359 OpenJDK Buffer overflow in image processing (6726779) https://bugzilla.redhat.com/show_bug.cgi?id=472212
[ 7 ] Bug #472213 - CVE-2008-5351 OpenJDK UTF-8 decoder accepts non-shortest form sequences (4486841) https://bugzilla.redhat.com/show_bug.cgi?id=472213
[ 8 ] Bug #472218 - CVE-2008-5356 OpenJDK Font processing vulnerability (6733336) https://bugzilla.redhat.com/show_bug.cgi?id=472218
[ 9 ] Bug #472233 - CVE-2008-5352 OpenJDK Jar200 Decompression buffer overflow (6755943) https://bugzilla.redhat.com/show_bug.cgi?id=472233
[ 10 ] Bug #472234 - CVE-2008-5358 OpenJDK Buffer Overflow in GIF image processing (6766136) https://bugzilla.redhat.com/show_bug.cgi?id=472234
[ 11 ] Bug #472224 - CVE-2008-5353 OpenJDK calender object deserialization allows privilege escalation (6734167) https://bugzilla.redhat.com/show_bug.cgi?id=472224
[ 12 ] Bug #472228 - CVE-2008-5354 OpenJDK Privilege escalation in command line applications (6733959) https://bugzilla.redhat.com/show_bug.cgi?id=472228
[ 13 ] Bug #472231 - CVE-2008-5357 OpenJDK Truetype Font processing vulnerability (6751322) https://bugzilla.redhat.com/show_bug.cgi?id=472231

Alerts:
SuSE SUSE-SR:2009:017 2009-10-26
Gentoo 200911-02 2009-11-17
SuSE SUSE-SR:2009:016 2009-10-13
SuSE SUSE-SR:2009:010 2009-05-12
SuSE SUSE-SA:2009:018 2009-04-07
Fedora FEDORA-2009-3058 2009-03-26
Red Hat RHSA-2009:0369-01 2009-03-25
SuSE SUSE-SR:2009:006 2009-03-10
Red Hat RHSA-2009:0445-01 2009-04-23
Ubuntu USN-713-1 2009-01-27
SuSE SUSE-SA:2009:007 2009-01-29
Fedora FEDORA-2008-10913 2008-12-07
Fedora FEDORA-2008-10860 2008-12-07
Red Hat RHSA-2009:0015-01 2009-01-13
Red Hat RHSA-2009:0016-01 2009-01-13
SuSE SUSE-SA:2009:001 2009-01-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds