LWN.net Logo

java: information disclosure

Package(s):java-1.6.0-sun CVE #(s):CVE-2010-0886 CVE-2010-0887
Created:April 20, 2010 Updated:July 21, 2010
Description: From the Oracle advisory:

This Security Alert addresses security issues CVE-2010-0886 and CVE-2010-0887, which are vulnerabilities in desktop Java running in web browsers only; these vulnerabilities are not present in Java running on servers or standalone Java desktop applications and do not impact any Oracle server based software. The desktop vulnerabilities are in the Java Deployment Toolkit and the new Java Plug-in that are included in various Oracle Java SE and Java for Business releases. They only affect Java when running in a 32-bit web browser. These vulnerabilities may be remotely exploitable without authentication, i.e., they may be exploited over a network without the need for a username and password. For a successful exploit, a user running an affected release in their browser will need to visit a malicious web page that exploits this vulnerability. Successful exploits can impact the availability, integrity, and confidentiality of the user's system.

Alerts:
Red Hat RHSA-2010:0356-02 2010-04-19
Red Hat RHSA-2010:0549-01 2010-07-21
Gentoo 201006-18 2010-06-04

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds