|
|
Subscribe / Log in / New account

java: multiple vulnerabilities

Package(s):java-1.6.0-openjdk CVE #(s):CVE-2012-1711 CVE-2012-1713 CVE-2012-1716 CVE-2012-1717 CVE-2012-1718 CVE-2012-1719 CVE-2012-1723 CVE-2012-1724 CVE-2012-1725
Created:June 13, 2012 Updated:September 28, 2012
Description: From the Red Hat advisory:

Multiple flaws were discovered in the CORBA (Common Object Request Broker Architecture) implementation in Java. A malicious Java application or applet could use these flaws to bypass Java sandbox restrictions or modify immutable object data. (CVE-2012-1711, CVE-2012-1719)

It was discovered that the SynthLookAndFeel class from Swing did not properly prevent access to certain UI elements from outside the current application context. A malicious Java application or applet could use this flaw to crash the Java Virtual Machine, or bypass Java sandbox restrictions. (CVE-2012-1716)

Multiple flaws were discovered in the font manager's layout lookup implementation. A specially-crafted font file could cause the Java Virtual Machine to crash or, possibly, execute arbitrary code with the privileges of the user running the virtual machine. (CVE-2012-1713)

Multiple flaws were found in the way the Java HotSpot Virtual Machine verified the bytecode of the class file to be executed. A specially-crafted Java application or applet could use these flaws to crash the Java Virtual Machine, or bypass Java sandbox restrictions. (CVE-2012-1723, CVE-2012-1725)

It was discovered that the Java XML parser did not properly handle certain XML documents. An attacker able to make a Java application parse a specially-crafted XML file could use this flaw to make the XML parser enter an infinite loop. (CVE-2012-1724)

It was discovered that the Java security classes did not properly handle Certificate Revocation Lists (CRL). CRL containing entries with duplicate certificate serial numbers could have been ignored. (CVE-2012-1718)

It was discovered that various classes of the Java Runtime library could create temporary files with insecure permissions. A local attacker could use this flaw to gain access to the content of such temporary files. (CVE-2012-1717)

Alerts:
Gentoo 201406-32 icedtea-bin 2014-06-29
Gentoo 201401-30 oracle-jdk-bin 2014-01-26
SUSE SUSE-SU-2012:1265-1 IBM Java 2012-09-28
SUSE SUSE-SU-2012:1231-1 IBM Java 2012-09-25
Red Hat RHSA-2012:1289-01 java-1.7.0-ibm 2012-09-18
SUSE SUSE-SU-2012:1204-1 IBM Java 2012-09-18
SUSE SUSE-SU-2012:1177-1 IBM Java 2012-09-14
Red Hat RHSA-2012:1467-01 java-1.7.0-ibm 2012-11-15
Red Hat RHSA-2012:1245-01 java-1.5.0-ibm 2012-09-07
Red Hat RHSA-2012:1243-01 java-1.4.2-ibm 2012-09-07
Red Hat RHSA-2012:1238-01 java-1.6.0-ibm 2012-09-06
Ubuntu USN-1505-2 icedtea-web 2012-08-29
Ubuntu USN-1505-1 icedtea-web, openjdk-6 2012-07-12
CentOS CESA-2012:1009 java-1.7.0-openjdk 2012-07-10
Scientific Linux SL-java-20120705 java-1.6.0-sun 2012-07-05
Debian DSA-2507-1 openjdk-6 2012-07-04
openSUSE openSUSE-SU-2012:0828-1 java 2012-07-04
Oracle ELSA-2012-1009 java-1.7.0-openjdk 2012-06-30
Mageia MGASA-2012-0130 java-1.6.0-openjdk 2012-06-27
Red Hat RHSA-2012:0734-01 java-1.6.0-sun 2012-06-13
Red Hat RHSA-2012:0729-01 java-1.6.0-openjdk 2012-06-13
Fedora FEDORA-2012-9593 java-1.7.0-openjdk 2012-06-17
Fedora FEDORA-2012-9590 java-1.7.0-openjdk 2012-06-17
Red Hat RHSA-2012:1019-01 java-1.7.0-oracle 2012-06-20
Red Hat RHSA-2012:1009-01 java-1.7.0-openjdk 2012-06-20
Fedora FEDORA-2012-9541 java-1.6.0-openjdk 2012-06-16
Scientific Linux SL-java-20120613 java-1.6.0-openjdk 2012-06-13
Scientific Linux SL-java-20120613 java-1.6.0-openjdk 2012-06-13
Mandriva MDVSA-2012:095 java-1.6.0-openjdk 2012-06-18
Fedora FEDORA-2012-9545 java-1.6.0-openjdk 2012-06-16
SUSE SUSE-SU-2012:0762-1 java-1_6_0-openjdk 2012-06-19
Oracle ELSA-2012-0729 java-1.6.0-openjdk 2012-06-14
Oracle ELSA-2012-0730 java-1.6.0-openjdk 2012-06-14
CentOS CESA-2012:0729 java-1.6.0-openjdk 2012-06-13
CentOS CESA-2012:0730 java-1.6.0-openjdk 2012-06-13
Red Hat RHSA-2012:0730-01 java-1.6.0-openjdk 2012-06-13

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds