Oval Definition:oval:org.mitre.oval:def:13150
Revision Date:2014-06-30Version:20
Title:USN-923-1 -- openjdk-6 vulnerabilities
Description:Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3 protocols. If an attacker could perform a man in the middle attack at the start of a TLS connection, the attacker could inject arbitrary content at the beginning of the user�s session. It was discovered that Loader-constraint table, Policy/PolicyFile, Inflater/Deflater, drag/drop access, and deserialization did not correctly handle certain sensitive objects. If a user were tricked into running a specially crafted applet, private information could be leaked to a remote attacker, leading to a loss of privacy. It was discovered that AtomicReferenceArray, System.arraycopy, InetAddress, and HashAttributeSet did not correctly handle certain situations. If a remote attacker could trigger specific error conditions, a Java application could crash, leading to a denial of service. It was discovered that Pack200, CMM readMabCurveData, ImagingLib, and the AWT library did not correctly check buffer lengths. If a user or automated system were tricked into handling specially crafted JAR files or images, a remote attacker could crash the Java application or possibly gain user privileges . It was discovered that applets did not correctly handle certain trust chains. If a user were tricked into running a specially crafted applet, a remote attacker could possibly run untrusted code with user privileges
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-3555
CVE-2010-0082
CVE-2010-0084
CVE-2010-0085
CVE-2010-0088
CVE-2010-0091
CVE-2010-0092
CVE-2010-0093
CVE-2010-0094
CVE-2010-0095
CVE-2010-0837
CVE-2010-0838
CVE-2010-0840
CVE-2010-0845
CVE-2010-0847
CVE-2010-0848
USN-923-1
USN-923-1
Platform(s):Ubuntu 8.04
Ubuntu 8.10
Ubuntu 9.04
Ubuntu 9.10
Product(s):openjdk-6
Definition Synopsis
  • Release section
  • Ubuntu 8.04 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND Packages section
  • openjdk-6-jre-lib DPKG is earlier than 6b11-2ubuntu2.2
  • OR openjdk-6-doc DPKG is earlier than 6b11-2ubuntu2.2
  • OR openjdk-6-source DPKG is earlier than 6b11-2ubuntu2.2
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is amd64
  • OR Installed architecture is lpia
  • OR Installed architecture is i386
  • AND Packages section
  • openjdk-6-jre-headless DPKG is earlier than 6b11-2ubuntu2.2
  • OR openjdk-6-demo DPKG is earlier than 6b11-2ubuntu2.2
  • OR openjdk-6-dbg DPKG is earlier than 6b11-2ubuntu2.2
  • OR openjdk-6-jdk DPKG is earlier than 6b11-2ubuntu2.2
  • OR openjdk-6-jre DPKG is earlier than 6b11-2ubuntu2.2
  • OR Release section
  • Ubuntu 8.10 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND Packages section
  • openjdk-6-jre-lib DPKG is earlier than 6b12-0ubuntu6.7
  • OR openjdk-6-doc DPKG is earlier than 6b12-0ubuntu6.7
  • OR openjdk-6-source-files DPKG is earlier than 6b12-0ubuntu6.7
  • OR openjdk-6-source DPKG is earlier than 6b12-0ubuntu6.7
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is amd64
  • OR Installed architecture is lpia
  • OR Installed architecture is i386
  • AND Packages section
  • openjdk-6-jre DPKG is earlier than 6b12-0ubuntu6.7
  • OR openjdk-6-jre-headless DPKG is earlier than 6b12-0ubuntu6.7
  • OR openjdk-6-demo DPKG is earlier than 6b12-0ubuntu6.7
  • OR openjdk-6-dbg DPKG is earlier than 6b12-0ubuntu6.7
  • OR openjdk-6-jdk DPKG is earlier than 6b12-0ubuntu6.7
  • OR icedtea6-plugin DPKG is earlier than 6b12-0ubuntu6.7
  • OR Release section
  • Ubuntu 9.10 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND Packages section
  • openjdk-6-jre-lib DPKG is earlier than 6b16-1.6.1-3ubuntu3
  • OR openjdk-6-doc DPKG is earlier than 6b16-1.6.1-3ubuntu3
  • OR openjdk-6-source DPKG is earlier than 6b16-1.6.1-3ubuntu3
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • openjdk-6-jre DPKG is earlier than 6b16-1.6.1-3ubuntu3
  • OR openjdk-6-jre-headless DPKG is earlier than 6b16-1.6.1-3ubuntu3
  • OR openjdk-6-demo DPKG is earlier than 6b16-1.6.1-3ubuntu3
  • OR openjdk-6-dbg DPKG is earlier than 6b16-1.6.1-3ubuntu3
  • OR openjdk-6-jdk DPKG is earlier than 6b16-1.6.1-3ubuntu3
  • OR icedtea6-plugin DPKG is earlier than 6b16-1.6.1-3ubuntu3
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is lpia
  • OR Installed architecture is powerpc
  • AND Packages section
  • icedtea-6-jre-cacao DPKG is earlier than 6b16-1.6.1-3ubuntu3
  • OR openjdk-6-jre-zero DPKG is earlier than 6b16-1.6.1-3ubuntu3
  • OR Release section
  • Ubuntu 9.04 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND Packages section
  • openjdk-6-jre-lib DPKG is earlier than 6b14-1.4.1-0ubuntu13
  • OR openjdk-6-doc DPKG is earlier than 6b14-1.4.1-0ubuntu13
  • OR openjdk-6-source-files DPKG is earlier than 6b14-1.4.1-0ubuntu13
  • OR openjdk-6-source DPKG is earlier than 6b14-1.4.1-0ubuntu13
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is powerpc
  • OR Installed architecture is amd64
  • OR Installed architecture is lpia
  • OR Installed architecture is i386
  • AND Packages section
  • icedtea-6-jre-cacao DPKG is earlier than 6b14-1.4.1-0ubuntu13
  • OR openjdk-6-jre DPKG is earlier than 6b14-1.4.1-0ubuntu13
  • OR openjdk-6-jre-headless DPKG is earlier than 6b14-1.4.1-0ubuntu13
  • OR openjdk-6-demo DPKG is earlier than 6b14-1.4.1-0ubuntu13
  • OR openjdk-6-dbg DPKG is earlier than 6b14-1.4.1-0ubuntu13
  • OR openjdk-6-jdk DPKG is earlier than 6b14-1.4.1-0ubuntu13
  • OR icedtea6-plugin DPKG is earlier than 6b14-1.4.1-0ubuntu13
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is lpia
  • OR Installed architecture is amd64
  • OR Installed architecture is i386
  • AND openjdk-6-jre-zero DPKG is earlier than 6b14-1.4.1-0ubuntu13
  • BACK