[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

USN-1055-1 -- openjdk-6, openjdk-6b18 vulnerabilities

ID: oval:org.secpod.oval:def:700226Date: (C)2011-02-18   (M)2023-02-20
Class: PATCHFamily: unix




It was discovered that IcedTea for Java did not properly verify signatures when handling multiply signed or partially signed JAR files, allowing an attacker to cause code to execute that appeared to come from a verified source. USN 1052-1 fixed a vulnerability in OpenJDK for Ubuntu 9.10 and Ubuntu 10.04 LTS on all architectures, and Ubuntu 10.10 for all architectures except for the armel architecture. This update provides the corresponding update for Ubuntu 10.10 on the armel architecture. Original advisory details: It was discovered that the JNLP SecurityManager in IcedTea for Java OpenJDK in some instances failed to properly apply the intended scurity policy in its checkPermission method. This could allow an attacker to execute code with privileges that should have been prevented

Platform:
Ubuntu 10.10
Ubuntu 9.10
Ubuntu 10.04
Product:
openjdk-6
Reference:
USN-1055-1
CVE-2010-4351
CVE-2011-0025
CVE    2
CVE-2010-4351
CVE-2011-0025
CPE    3
cpe:/o:ubuntu:ubuntu_linux:10.04
cpe:/o:ubuntu:ubuntu_linux:9.10
cpe:/o:ubuntu:ubuntu_linux:10.10

© SecPod Technologies