LWN.net Logo

java-1.6.0-sun: multiple vulnerabilities

Package(s):java-1.6.0-sun CVE #(s):CVE-2006-2426 CVE-2009-1093 CVE-2009-1094 CVE-2009-1095 CVE-2009-1096 CVE-2009-1097 CVE-2009-1098 CVE-2009-1099 CVE-2009-1100 CVE-2009-1101 CVE-2009-1102 CVE-2009-1103 CVE-2009-1104 CVE-2009-1105 CVE-2009-1106 CVE-2009-1107
Created:March 26, 2009 Updated:November 18, 2009
Description: Java 1.6.0 has a long list of vulnerabilities. From the Red Hat alert:

CVE-2006-2426 Untrusted applet causes DoS by filling up disk space

CVE-2009-1101 OpenJDK JAX-WS service endpoint remote Denial-of-Service

CVE-2009-1093 OpenJDK remote LDAP Denial-Of-Service

CVE-2009-1094 OpenJDK LDAP client remote code execution

CVE-2009-1095 CVE-2009-1096 OpenJDK Pack200 Buffer overflow vulnerability

CVE-2009-1102 OpenJDK code generation vulnerability

CVE-2009-1097 OpenJDK PNG processing buffer overflow vulnerability

CVE-2009-1098 OpenJDK GIF processing buffer overflow vulnerability

CVE-2009-1099 OpenJDK: Type1 font processing buffer overflow vulnerability

CVE-2009-1100 OpenJDK: DoS (disk consumption) via handling of temporary font files

CVE-2009-1103 OpenJDK: Files disclosure, arbitrary code execution via "deserializing applets"

CVE-2009-1104 OpenJDK: Intended access restrictions bypass via LiveConnect

CVE-2009-1105 OpenJDK: Possibility of trusted applet run in older, vulnerable version of JRE

CVE-2009-1106 OpenJDK: Improper parsing of crossdomain.xml files (intended access restriction bypass)

CVE-2009-1107 OpenJDK: Signed applet remote misuse possibility

Alerts:
Red Hat RHSA-2009:1198-02 2009-08-06
Mandriva MDVSA-2009:162 2009-07-28
SuSE SUSE-SA:2009:036 2009-07-02
Mandriva MDVSA-2009:137 2009-06-20
Gentoo 200911-02 2009-11-17
SuSE SUSE-SR:2009:011 2009-06-09
SuSE SUSE-SA:2009:029 2009-05-25
Red Hat RHSA-2009:1038-01 2009-05-18
Debian DSA-1769-1 2009-04-11
CentOS CESA-2009:0377 2009-04-08
Red Hat RHSA-2009:0377-01 2009-04-07
SuSE SUSE-SA:2009:016 2009-04-03
Ubuntu USN-748-1 2009-03-26
Red Hat RHSA-2009:0394-01 2009-03-26
Red Hat RHSA-2009:0392-01 2009-03-26

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds