java-1.6.0-openjdk: multiple vulnerabilities
| Package(s): | java-1.6.0-openjdk | CVE #(s): | CVE-2009-2475 CVE-2009-2476 CVE-2009-2625 CVE-2009-2670 CVE-2009-2671 CVE-2009-2672 CVE-2009-2673 CVE-2009-2674 CVE-2009-2675 CVE-2009-2689 CVE-2009-2690 CVE-2009-1896 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | August 7, 2009 | Updated: | November 30, 2009 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Fedora advisory:
CVE-2009-2475 OpenJDK information leaks in mutable variables CVE-2009-2476 OpenJDK OpenType checks can be bypassed CVE-2009-2625 OpenJDK XML parsing Denial-Of-Service CVE-2009-2670 OpenJDK Untrusted applet System properties access CVE-2009-2671 CVE-2009-2672 OpenJDK Proxy mechanism information leaks CVE-2009-2673 OpenJDK proxy mechanism allows non-authorized socket connections CVE-2009-2674 Java Web Start Buffer JPEG processing integer overflow CVE-2009-2675 Java Web Start Buffer unpack200 processing integer overflow CVE-2009-2689 OpenJDK JDK13Services grants unnecessary privileges CVE-2009-2690 OpenJDK private variable information disclosure CVE-2009-1896 openjdk/netx grants privileges for signed jars to bundled unsigned jars | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
