LWN.net Logo

java: multiple vulnerabilities

Package(s):java-1.6.0-openjdk CVE #(s):CVE-2011-3521 CVE-2011-3544 CVE-2011-3547 CVE-2011-3548 CVE-2011-3551 CVE-2011-3552 CVE-2011-3553 CVE-2011-3554 CVE-2011-3556 CVE-2011-3557 CVE-2011-3558 CVE-2011-3560
Created:October 19, 2011 Updated:February 6, 2013
Description: From the Red Hat advisory:

A flaw was found in the Java RMI (Remote Method Invocation) registry implementation. A remote RMI client could use this flaw to execute arbitrary code on the RMI server running the registry. (CVE-2011-3556)

A flaw was found in the Java RMI registry implementation. A remote RMI client could use this flaw to execute code on the RMI server with unrestricted privileges. (CVE-2011-3557)

A flaw was found in the IIOP (Internet Inter-Orb Protocol) deserialization code. An untrusted Java application or applet running in a sandbox could use this flaw to bypass sandbox restrictions by deserializing specially-crafted input. (CVE-2011-3521)

It was found that the Java ScriptingEngine did not properly restrict the privileges of sandboxed applications. An untrusted Java application or applet running in a sandbox could use this flaw to bypass sandbox restrictions. (CVE-2011-3544)

A flaw was found in the AWTKeyStroke implementation. An untrusted Java application or applet running in a sandbox could use this flaw to bypass sandbox restrictions. (CVE-2011-3548)

An integer overflow flaw, leading to a heap-based buffer overflow, was found in the Java2D code used to perform transformations of graphic shapes and images. An untrusted Java application or applet running in a sandbox could use this flaw to bypass sandbox restrictions. (CVE-2011-3551)

An insufficient error checking flaw was found in the unpacker for JAR files in pack200 format. A specially-crafted JAR file could use this flaw to crash the Java Virtual Machine (JVM) or, possibly, execute arbitrary code with JVM privileges. (CVE-2011-3554)

It was found that HttpsURLConnection did not perform SecurityManager checks in the setSSLSocketFactory method. An untrusted Java application or applet running in a sandbox could use this flaw to bypass connection restrictions defined in the policy. (CVE-2011-3560)

An information leak flaw was found in the InputStream.skip implementation. An untrusted Java application or applet could possibly use this flaw to obtain bytes skipped by other threads. (CVE-2011-3547)

A flaw was found in the Java HotSpot virtual machine. An untrusted Java application or applet could use this flaw to disclose portions of the VM memory, or cause it to crash. (CVE-2011-3558)

The Java API for XML Web Services (JAX-WS) implementation in OpenJDK was configured to include the stack trace in error messages sent to clients. A remote client could possibly use this flaw to obtain sensitive information. (CVE-2011-3553)

It was found that Java applications running with SecurityManager restrictions were allowed to use too many UDP sockets by default. If multiple instances of a malicious application were started at the same time, they could exhaust all available UDP sockets on the system. (CVE-2011-3552)

Alerts:
Debian DSA-2358-1 2011-12-05
SUSE SUSE-SU-2011:1298-1 2011-12-02
Debian DSA-2356-1 2011-12-01
Red Hat RHSA-2011:1478-01 2011-11-24
Mandriva MDVSA-2011:170 2011-11-11
Ubuntu USN-1263-1 2011-11-16
Fedora FEDORA-2011-15555 2011-11-07
Scientific Linux SL-java-20111019 2011-10-19
Gentoo 201111-02 2011-11-05
openSUSE openSUSE-SU-2011:1196-1 2011-10-28
Scientific Linux SL-java-20111018 2011-10-18
Fedora FEDORA-2011-14648 2011-10-20
Fedora FEDORA-2011-14638 2011-10-20
CentOS CESA-2011:1380 2011-10-19
Red Hat RHSA-2011:1384-01 2011-10-19
Red Hat RHSA-2011:1380-01 2011-10-18
Red Hat RHSA-2012:0006-01 2012-01-09
Red Hat RHSA-2012:0034-01 2012-01-18
SUSE SUSE-SU-2012:0114-1 2012-01-23
SUSE SUSE-SU-2012:0122-1 2012-01-26
Fedora FEDORA-2012-1690 2012-02-15
SUSE SUSE-SU-2012:0122-2 2012-02-23
SUSE SUSE-SU-2012:0114-2 2012-03-06
Red Hat RHSA-2012:0508-01 2012-04-23
SUSE SUSE-SU-2012:0602-1 2012-05-09
Fedora FEDORA-2012-16351 2012-10-18
Fedora FEDORA-2013-1898 2013-02-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds