LWN.net Logo

openjdk: privilege escalation

Package(s):openjdk-6 CVE #(s):CVE-2011-0706
Created:March 1, 2011 Updated:June 15, 2011
Description: From the CVE entry:

The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor."

Alerts:
Mandriva MDVSA-2011:054 2011-03-27
Ubuntu USN-1079-3 2011-03-17
Ubuntu USN-1079-2 2011-03-15
openSUSE openSUSE-SU-2011:0155-1 2011-03-07
Ubuntu USN-1079-1 2011-03-01
Debian DSA-2224-1 2011-04-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds