[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2010:084 -- Mandriva java-1.6.0-openjdk

ID: oval:org.secpod.oval:def:301167Date: (C)2012-01-07   (M)2024-02-19
Class: PATCHFamily: unix




Multiple Java OpenJDK security vulnerabilities has been identified and fixed: - TLS: MITM attacks via session renegotiation . - Loader-constraint table allows arrays instead of only the b ase-classes . - Policy/PolicyFile leak dynamic ProtectionDomains. - File TOCTOU deserialization vulnerability . - Inflater/Deflater clone issues . - Unsigned applet can retrieve the dragged information before drop action occurs . - AtomicReferenceArray causes SIGSEGV -> SEGV_MAPERR error . - System.arraycopy unable to reference elements beyond Integer.MAX_VALUE bytes . - Deserialization of RMIConnectionImpl objects should enforce stricter checks . - Subclasses of InetAddress may incorrectly interpret network addresses . - JAR unpack200 must verify input parameters . - CMM readMabCurveData Buffer Overflow Vulnerability . - Applet Trusted Methods Chaining Privilege Escalation Vulner ability . - No ClassCastException for HashAttributeSet constructors if run with -Xcomp - ImagingLib arbitrary code execution vulnerability . - AWT Library Invalid Index Vulnerability . Additional security issues that was fixed with IcedTea6 1.6.2: - deprecate MD2 in SSL cert validation . - ICC_Profile file existence detection information leak . - JRE AWT setDifflCM stack overflow . - JRE AWT setBytePixels heap overflow . - JPEG Image Writer quantization problem . - ImageI/O JPEG heap overflow . - MessageDigest.isEqual introduces timing attack vulnerabilities . - OpenJDK ASN.1/DER input stream parser denial of service - GraphicsConfiguration information leak . - UI logging information leakage . - resurrected classloaders can still have children . - Numerous static security flaws in Swing . - Mutable statics in Windows PL&F . - zoneinfo file existence information leak . - BMP parsing DoS with UNC ICC links . Additionally Paulo Cesar Pereira de Andrade at Mandriva found and fixed a bug in IcedTea6 1.8 that is also applied to the provided packages: * plugin/icedteanp/IcedTeaNPPlugin.cc : Increment malloc size by one to account for NULL terminator. Bug# 474. Packages for 2009.0 are provided due to the Extended Maintenance Program.

Platform:
Mandriva Linux 2010.0
Mandriva Linux 2009.0
Mandriva Linux 2009.1
Product:
java-1.6.0-openjdk
Reference:
MDVSA-2010:084
CVE-2010-0848
CVE-2010-0847
CVE-2010-0845
CVE-2010-0840
CVE-2010-0838
CVE-2010-0837
CVE-2010-0095
CVE-2010-0094
CVE-2010-0093
CVE-2010-0092
CVE-2010-0091
CVE-2010-0088
CVE-2010-0085
CVE-2010-0084
CVE-2010-0082
CVE-2009-3885
CVE-2009-3884
CVE-2009-3883
CVE-2009-3882
CVE-2009-3881
CVE-2009-3880
CVE-2009-3879
CVE-2009-3877
CVE-2009-3876
CVE-2009-3875
CVE-2009-3874
CVE-2009-3871
CVE-2009-3873
CVE-2009-3728
CVE-2009-3869
CVE-2009-2409
CVE-2009-3555
CVE    32
CVE-2009-3728
CVE-2009-3869
CVE-2009-3884
CVE-2009-3885
...
CPE    3
cpe:/o:mandriva:linux:2009.0
cpe:/o:mandriva:linux:2009.1
cpe:/o:mandriva:linux:2010.0

© SecPod Technologies