Oval Definition:oval:org.mitre.oval:def:13241
Revision Date:2014-06-30Version:20
Title:USN-1079-1 -- openjdk-6 vulnerabilities
Description:It was discovered that untrusted Java applets could create domain name resolution cache entries, allowing an attacker to manipulate name resolution within the JVM. It was discovered that the Java launcher did not did not properly setup the LD_LIBRARY_PATH environment variable. A local attacker could exploit this to execute arbitrary code as the user invoking the program. It was discovered that within the Swing library, forged timer events could allow bypass of SecurityManager checks. This could allow an attacker to access restricted resources. It was discovered that certain bytecode combinations confused memory management within the HotSpot JVM. This could allow an attacker to cause a denial of service through an application crash or possibly inject code. It was discovered that the way JAXP components were handled allowed them to be manipulated by untrusted applets. An attacker could use this to bypass XML processing restrictions and elevate privileges. It was discovered that the Java2D subcomponent, when processing broken CFF fonts could leak system properties. It was discovered that a flaw in the XML Digital Signature component could allow an attacker to cause untrusted code to replace the XML Digital Signature Transform or C14N algorithm implementations. Konstantin Preißer and others discovered that specific double literals were improperly handled, allowing a remote attacker to cause a denial of service. It was discovered that the JNLPClassLoader class when handling multiple signatures allowed remote attackers to gain privileges due to the assignment of an inappropriate security descriptor
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2010-4448
CVE-2010-4450
CVE-2010-4465
CVE-2010-4469
CVE-2010-4470
CVE-2010-4471
CVE-2010-4472
CVE-2010-4476
CVE-2011-0706
USN-1079-1
USN-1079-1
Platform(s):Ubuntu 10.04
Ubuntu 10.10
Ubuntu 9.10
Product(s):openjdk-6
Definition Synopsis
  • Release section
  • Ubuntu 10.10 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • openjdk-6-jre-lib DPKG is earlier than 6b20-1.9.7-0ubuntu1
  • OR openjdk-6-doc DPKG is earlier than 6b20-1.9.7-0ubuntu1
  • OR openjdk-6-source DPKG is earlier than 6b20-1.9.7-0ubuntu1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is powerpc
  • OR Installed architecture is amd64
  • OR Installed architecture is i386
  • AND Packages section
  • icedtea-6-jre-cacao DPKG is earlier than 6b20-1.9.7-0ubuntu1
  • OR openjdk-6-jdk DPKG is earlier than 6b20-1.9.7-0ubuntu1
  • OR openjdk-6-jre DPKG is earlier than 6b20-1.9.7-0ubuntu1
  • OR openjdk-6-jre-headless DPKG is earlier than 6b20-1.9.7-0ubuntu1
  • OR openjdk-6-demo DPKG is earlier than 6b20-1.9.7-0ubuntu1
  • OR openjdk-6-dbg DPKG is earlier than 6b20-1.9.7-0ubuntu1
  • OR openjdk-6-jre-zero DPKG is earlier than 6b20-1.9.7-0ubuntu1
  • OR icedtea6-plugin DPKG is earlier than 6b20-1.9.7-0ubuntu1
  • OR Release section
  • Ubuntu 9.10 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • openjdk-6-jre-lib DPKG is earlier than 6b20-1.9.7-0ubuntu1~9.10.1
  • OR openjdk-6-doc DPKG is earlier than 6b20-1.9.7-0ubuntu1~9.10.1
  • OR openjdk-6-source DPKG is earlier than 6b20-1.9.7-0ubuntu1~9.10.1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is amd64
  • OR Installed architecture is lpia
  • OR Installed architecture is i386
  • AND Packages section
  • openjdk-6-jre DPKG is earlier than 6b20-1.9.7-0ubuntu1~9.10.1
  • OR openjdk-6-jre-headless DPKG is earlier than 6b20-1.9.7-0ubuntu1~9.10.1
  • OR openjdk-6-demo DPKG is earlier than 6b20-1.9.7-0ubuntu1~9.10.1
  • OR openjdk-6-dbg DPKG is earlier than 6b20-1.9.7-0ubuntu1~9.10.1
  • OR openjdk-6-jdk DPKG is earlier than 6b20-1.9.7-0ubuntu1~9.10.1
  • OR icedtea6-plugin DPKG is earlier than 6b20-1.9.7-0ubuntu1~9.10.1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is lpia
  • OR Installed architecture is amd64
  • OR Installed architecture is i386
  • AND Packages section
  • icedtea-6-jre-cacao DPKG is earlier than 6b20-1.9.7-0ubuntu1~9.10.1
  • OR openjdk-6-jre-zero DPKG is earlier than 6b20-1.9.7-0ubuntu1~9.10.1
  • OR Release section
  • Ubuntu 10.04 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • openjdk-6-jre-lib DPKG is earlier than 6b20-1.9.7-0ubuntu1~10.04.1
  • OR openjdk-6-doc DPKG is earlier than 6b20-1.9.7-0ubuntu1~10.04.1
  • OR openjdk-6-source DPKG is earlier than 6b20-1.9.7-0ubuntu1~10.04.1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is powerpc
  • OR Installed architecture is amd64
  • OR Installed architecture is i386
  • AND Packages section
  • openjdk-6-jre DPKG is earlier than 6b20-1.9.7-0ubuntu1~10.04.1
  • OR openjdk-6-jre-headless DPKG is earlier than 6b20-1.9.7-0ubuntu1~10.04.1
  • OR openjdk-6-demo DPKG is earlier than 6b20-1.9.7-0ubuntu1~10.04.1
  • OR openjdk-6-dbg DPKG is earlier than 6b20-1.9.7-0ubuntu1~10.04.1
  • OR openjdk-6-jdk DPKG is earlier than 6b20-1.9.7-0ubuntu1~10.04.1
  • OR icedtea6-plugin DPKG is earlier than 6b20-1.9.7-0ubuntu1~10.04.1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is powerpc
  • AND Packages section
  • icedtea-6-jre-cacao DPKG is earlier than 6b20-1.9.7-0ubuntu1~10.04.1
  • OR openjdk-6-jre-zero DPKG is earlier than 6b20-1.9.7-0ubuntu1~10.04.1
  • BACK