LWN.net Logo

java: multiple vulnerabilities

Package(s):java-1.6.0-openjdk CVE #(s):CVE-2012-1711 CVE-2012-1713 CVE-2012-1716 CVE-2012-1717 CVE-2012-1718 CVE-2012-1719 CVE-2012-1723 CVE-2012-1724 CVE-2012-1725
Created:June 13, 2012 Updated:September 28, 2012
Description: From the Red Hat advisory:

Multiple flaws were discovered in the CORBA (Common Object Request Broker Architecture) implementation in Java. A malicious Java application or applet could use these flaws to bypass Java sandbox restrictions or modify immutable object data. (CVE-2012-1711, CVE-2012-1719)

It was discovered that the SynthLookAndFeel class from Swing did not properly prevent access to certain UI elements from outside the current application context. A malicious Java application or applet could use this flaw to crash the Java Virtual Machine, or bypass Java sandbox restrictions. (CVE-2012-1716)

Multiple flaws were discovered in the font manager's layout lookup implementation. A specially-crafted font file could cause the Java Virtual Machine to crash or, possibly, execute arbitrary code with the privileges of the user running the virtual machine. (CVE-2012-1713)

Multiple flaws were found in the way the Java HotSpot Virtual Machine verified the bytecode of the class file to be executed. A specially-crafted Java application or applet could use these flaws to crash the Java Virtual Machine, or bypass Java sandbox restrictions. (CVE-2012-1723, CVE-2012-1725)

It was discovered that the Java XML parser did not properly handle certain XML documents. An attacker able to make a Java application parse a specially-crafted XML file could use this flaw to make the XML parser enter an infinite loop. (CVE-2012-1724)

It was discovered that the Java security classes did not properly handle Certificate Revocation Lists (CRL). CRL containing entries with duplicate certificate serial numbers could have been ignored. (CVE-2012-1718)

It was discovered that various classes of the Java Runtime library could create temporary files with insecure permissions. A local attacker could use this flaw to gain access to the content of such temporary files. (CVE-2012-1717)

Alerts:
Red Hat RHSA-2012:0729-01 2012-06-13
Red Hat RHSA-2012:0730-01 2012-06-13
Scientific Linux SL-java-20120613 2012-06-13
Scientific Linux SL-java-20120613 2012-06-13
Red Hat RHSA-2012:0734-01 2012-06-13
CentOS CESA-2012:0730 2012-06-13
CentOS CESA-2012:0729 2012-06-13
Oracle ELSA-2012-0730 2012-06-14
Oracle ELSA-2012-0729 2012-06-14
Fedora FEDORA-2012-9545 2012-06-16
Fedora FEDORA-2012-9541 2012-06-16
Fedora FEDORA-2012-9590 2012-06-17
Fedora FEDORA-2012-9593 2012-06-17
Mandriva MDVSA-2012:095 2012-06-18
Red Hat RHSA-2012:1009-01 2012-06-20
Red Hat RHSA-2012:1019-01 2012-06-20
SUSE SUSE-SU-2012:0762-1 2012-06-19
Mageia MGASA-2012-0130 2012-06-27
Oracle ELSA-2012-1009 2012-06-30
openSUSE openSUSE-SU-2012:0828-1 2012-07-04
Debian DSA-2507-1 2012-07-04
Scientific Linux SL-java-20120705 2012-07-05
CentOS CESA-2012:1009 2012-07-10
Ubuntu USN-1505-1 2012-07-12
Ubuntu USN-1505-2 2012-08-29
Red Hat RHSA-2012:1238-01 2012-09-06
Red Hat RHSA-2012:1243-01 2012-09-07
Red Hat RHSA-2012:1245-01 2012-09-07
SUSE SUSE-SU-2012:1177-1 2012-09-14
SUSE SUSE-SU-2012:1204-1 2012-09-18
Red Hat RHSA-2012:1289-01 2012-09-18
SUSE SUSE-SU-2012:1231-1 2012-09-25
SUSE SUSE-SU-2012:1265-1 2012-09-28
Red Hat RHSA-2012:1467-01 2012-11-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds