[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253562

 
 

909

 
 

197267

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SA:2009:043 -- SUSE java-1_5_0-sun,java-1_6_0-sun remote code execution

ID: oval:org.secpod.oval:def:400074Date: (C)2012-01-31   (M)2022-03-02
Class: PATCHFamily: unix




The Sun Java JRE /JDK 5 was updated to Update 20 fixing various security issues. CVE-2009-2670: The audio system in Sun Java Runtime Environment in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by untrusted applets and Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties. CVE-2009-2671: The SOCKS proxy implementation in Sun Java Runtime Environment in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to discover the user name of the account that invoked an untrusted applet or Java Web Start application via unspecified vectors. CVE-2009-2672: The proxy mechanism implementation in Sun Java Runtime Environment in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted applets and Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors. CVE-2009-2673: The proxy mechanism implementation in Sun Java Runtime Environment in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword. CVE-2009-2674: Integer overflow in Sun Java Runtime Environment in JDK and JRE 6 before Update 15 allows context-dependent attackers to gain privileges via vectors involving an untrusted Java Web Start application that grants permissions to itself, related to parsing of JPEG images. CVE-2009-2675: Integer overflow in the unpack200 utility in Sun Java Runtime Environment in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via vectors involving an untrusted applet or Java Web Start application that grants permissions to itself, related to decompression. CVE-2009-2676: Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier +and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet.

Platform:
openSUSE 10.3
openSUSE 11.1
openSUSE 11.0
Product:
java-1_5_0-sun
java-1_6_0-sun
Reference:
SUSE-SA:2009:043
CVE-2009-2670
CVE-2009-2671
CVE-2009-2672
CVE-2009-2673
CVE-2009-2674
CVE-2009-2675
CVE-2009-2676
CVE    7
CVE-2009-2674
CVE-2009-2675
CVE-2009-2676
CVE-2009-2670
...
CPE    3
cpe:/o:opensuse:opensuse:11.1
cpe:/o:opensuse:opensuse:11.0
cpe:/o:opensuse:opensuse:10.3

© SecPod Technologies