LWN.net Logo

java: multiple vulnerabilities

Package(s):java CVE #(s):CVE-2012-5070 CVE-2012-5074 CVE-2012-5076 CVE-2012-5087 CVE-2012-5088
Created:October 17, 2012 Updated:November 21, 2012
Description: From the Red Hat advisory:

It was discovered that the JMX component in OpenJDK could perform certain actions in an insecure manner. An untrusted Java application or applet could possibly use these flaws to disclose sensitive information. (CVE-2012-5070, CVE-2012-5075)

The default Java security properties configuration did not restrict access to certain com.sun.org.glassfish packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. This update lists those packages as restricted. (CVE-2012-5076, CVE-2012-5074)

Multiple improper permission check issues were discovered in the Beans, Libraries, Swing, and JMX components in OpenJDK. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. (CVE-2012-5086, CVE-2012-5087, CVE-2012-5088, CVE-2012-5084, CVE-2012-5089)

Alerts:
Red Hat RHSA-2012:1386-01 2012-10-17
CentOS CESA-2012:1386 2012-10-17
Oracle ELSA-2012-1386 2012-10-18
Red Hat RHSA-2012:1391-01 2012-10-18
Scientific Linux SL-java-20121019 2012-10-19
SUSE SUSE-SU-2012:1398-1 2012-10-24
Mageia MGASA-2012-0306 2012-10-29
openSUSE openSUSE-SU-2012:1419-1 2012-10-31
Red Hat RHSA-2012:1467-01 2012-11-15
SUSE SUSE-SU-2012:1489-2 2012-11-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds