[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2507-1 openjdk-6 -- several issues

ID: oval:org.secpod.oval:def:600845Date: (C)2012-07-06   (M)2022-12-21
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform. CVE-2012-1711 CVE-2012-1719 Multiple errors in the CORBA implementation could lead to breakouts of the Java sandbox CVE-2012-1713 Missing input sanitising in the font manager could lead to the execution of arbitrary code. CVE-2012-1716 The SynthLookAndFeel Swing class could be abused to break out of the Java sandbox. CVE-2012-1717 Several temporary files were created insecurely, resulting in local information disclosure. CVE-2012-1718 Certificate revocation lists were incorrectly implemented. CVE-2012-1723 CVE-2012-1725 Validation errors in the bytecode verifier of the Hotspot VM could lead to breakouts of the Java sandbox. CVE-2012-1724 Missing input sanitising in the XML parser could lead to denial of service through an infinite loop.

Platform:
Debian 6.0
Product:
openjdk-6-jdk
Reference:
DSA-2507-1
CVE-2012-1711
CVE-2012-1713
CVE-2012-1716
CVE-2012-1717
CVE-2012-1718
CVE-2012-1719
CVE-2012-1723
CVE-2012-1724
CVE-2012-1725
CVE    9
CVE-2012-1718
CVE-2012-1719
CVE-2012-1711
CVE-2012-1713
...
CPE    2
cpe:/o:debian:debian_linux:6.x
cpe:/a:oracle:openjdk-6-jdk

© SecPod Technologies