User: Password:
|
|
Subscribe / Log in / New account

java: multiple vulnerabilities

Package(s):java CVE #(s):CVE-2012-5070 CVE-2012-5074 CVE-2012-5076 CVE-2012-5087 CVE-2012-5088
Created:October 17, 2012 Updated:November 21, 2012
Description: From the Red Hat advisory:

It was discovered that the JMX component in OpenJDK could perform certain actions in an insecure manner. An untrusted Java application or applet could possibly use these flaws to disclose sensitive information. (CVE-2012-5070, CVE-2012-5075)

The default Java security properties configuration did not restrict access to certain com.sun.org.glassfish packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. This update lists those packages as restricted. (CVE-2012-5076, CVE-2012-5074)

Multiple improper permission check issues were discovered in the Beans, Libraries, Swing, and JMX components in OpenJDK. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. (CVE-2012-5086, CVE-2012-5087, CVE-2012-5088, CVE-2012-5084, CVE-2012-5089)

Alerts:
Gentoo 201406-32 icedtea-bin 2014-06-29
Gentoo 201401-30 oracle-jdk-bin 2014-01-26
Mageia MGASA-2012-0306 java-1.7.0-openjdk 2012-10-29
Scientific Linux SL-java-20121019 java-1.7.0-openjdk 2012-10-19
Red Hat RHSA-2012:1391-01 java-1.7.0-oracle 2012-10-18
Oracle ELSA-2012-1386 java-1.7.0-openjdk 2012-10-18
CentOS CESA-2012:1386 java-1.7.0-openjdk 2012-10-17
Red Hat RHSA-2012:1386-01 java-1.7.0-openjdk 2012-10-17
SUSE SUSE-SU-2012:1398-1 OpenJDK 2012-10-24
SUSE SUSE-SU-2012:1489-2 IBM Java 1.7.0 2012-11-21
Red Hat RHSA-2012:1467-01 java-1.7.0-ibm 2012-11-15
openSUSE openSUSE-SU-2012:1419-1 java-1_7_0-openjdk 2012-10-31

(Log in to post comments)


Copyright © 2018, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds