Oval Definition:oval:org.mitre.oval:def:13305
Revision Date:2014-06-30Version:20
Title:USN-1010-1 -- openjdk-6, openjdk-6b18 vulnerabilities
Description:Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3 protocols. If an attacker could perform a man in the middle attack at the start of a TLS connection, the attacker could inject arbitrary content at the beginning of the user�s session. USN-923-1 disabled SSL/TLS renegotiation by default; this update implements the TLS Renegotiation Indication Extension as defined in RFC 5746, and thus supports secure renegotiation between updated clients and servers. It was discovered that the HttpURLConnection class did not validate request headers set by java applets, which could allow an attacker to trigger actions otherwise not allowed to HTTP clients. It was discovered that JNDI could leak information that would allow an attacker to access information about otherwise-protected internal network names. It was discovered that HttpURLConnection improperly handled the "chunked" transfer encoding method, which could allow attackers to conduct HTTP response splitting attacks. It was discovered that the NetworkInterface class improperly checked the network "connect" permissions for local network addresses. This could allow an attacker to read local network addresses. It was discovered that UIDefault.ProxyLazyValue had unsafe reflection usage, allowing an attacker to create objects. It was discovered that multiple flaws in the CORBA reflection implementation could allow an attacker to execute arbitrary code by misusing permissions granted to certain system objects. It was discovered that unspecified flaws in the Swing library could allow untrusted applications to modify the behavior and state of certain JDK classes. It was discovered that the privileged accept method of the ServerSocket class in the CORBA implementation allowed it to receive connections from any host, instead of just the host of the current connection. An attacker could use this flaw to bypass restrictions defined by network permissions. It was discovered that there exists a double free in java�s indexColorModel that could allow an attacker to cause an applet or application to crash, or possibly execute arbitrary code with the privilege of the user running the java applet or application. It was discovered that the Kerberos implementation improperly checked AP-REQ requests, which could allow an attacker to cause a denial of service against the receiving JVM. It was discovered that improper checks of unspecified image metadata in JPEGImageWriter.writeImage of the imageio API could allow an attacker to execute arbitrary code with the privileges of the user running a java applet or application. It was discovered that an unspecified vulnerability in the ICC profile handling code could allow an attacker to execute arbitrary code with the privileges of the user running a java applet or application. It was discovered that a miscalculation in the OpenType font rendering implementation would allow out-of-bounds memory access. This could allow an attacker to execute arbitrary code with the privileges of the user running a java application. It was discovered that an unspecified race condition in the way objects were deserialized could allow an attacker to cause an applet or application to misuse the privileges of the user running the java applet or application. It was discovered that the defaultReadObject of the Serialization API could be tricked into setting a volatile field multiple times. This could allow an attacker to execute arbitrary code with the privileges of the user running a java applet or application. It was discovered that the HttpURLConnection class did not validate request headers set by java applets, which could allow an attacker to trigger actions otherwise not allowed to HTTP clients. It was discovered that the HttpURLConnection class improperly checked whether the calling code was granted the "allowHttpTrace" permission, allowing an attacker to create HTTP TRACE requests
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-3555
CVE-2010-3541
CVE-2010-3548
CVE-2010-3549
CVE-2010-3551
CVE-2010-3553
CVE-2010-3554
CVE-2010-3557
CVE-2010-3561
CVE-2010-3562
CVE-2010-3564
CVE-2010-3565
CVE-2010-3566
CVE-2010-3567
CVE-2010-3568
CVE-2010-3569
CVE-2010-3573
CVE-2010-3574
USN-1010-1
USN-1010-1
Platform(s):Ubuntu 10.04
Ubuntu 10.10
Ubuntu 8.04
Ubuntu 9.10
Product(s):openjdk-6
openjdk-6b18
Definition Synopsis
  • Release section
  • Ubuntu 8.04 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND Packages section
  • openjdk-6-jre-lib DPKG is earlier than 6b18-1.8.2-4ubuntu1~8.04.1
  • OR openjdk-6-doc DPKG is earlier than 6b18-1.8.2-4ubuntu1~8.04.1
  • OR openjdk-6-source DPKG is earlier than 6b18-1.8.2-4ubuntu1~8.04.1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is powerpc
  • OR Installed architecture is amd64
  • OR Installed architecture is lpia
  • OR Installed architecture is i386
  • AND Packages section
  • openjdk-6-jre DPKG is earlier than 6b18-1.8.2-4ubuntu1~8.04.1
  • OR openjdk-6-jre-headless DPKG is earlier than 6b18-1.8.2-4ubuntu1~8.04.1
  • OR openjdk-6-demo DPKG is earlier than 6b18-1.8.2-4ubuntu1~8.04.1
  • OR openjdk-6-dbg DPKG is earlier than 6b18-1.8.2-4ubuntu1~8.04.1
  • OR openjdk-6-jdk DPKG is earlier than 6b18-1.8.2-4ubuntu1~8.04.1
  • OR icedtea6-plugin DPKG is earlier than 6b18-1.8.2-4ubuntu1~8.04.1
  • OR Release section
  • Ubuntu 10.10 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND Packages section
  • openjdk-6-jre-lib DPKG is earlier than 6b20-1.9.1-1ubuntu3
  • OR openjdk-6-doc DPKG is earlier than 6b20-1.9.1-1ubuntu3
  • OR openjdk-6-source DPKG is earlier than 6b20-1.9.1-1ubuntu3
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is powerpc
  • OR Installed architecture is amd64
  • OR Installed architecture is i386
  • AND Packages section
  • icedtea-6-jre-cacao DPKG is earlier than 6b20-1.9.1-1ubuntu3
  • OR openjdk-6-jdk DPKG is earlier than 6b20-1.9.1-1ubuntu3
  • OR openjdk-6-jre DPKG is earlier than 6b20-1.9.1-1ubuntu3
  • OR openjdk-6-jre-headless DPKG is earlier than 6b20-1.9.1-1ubuntu3
  • OR openjdk-6-demo DPKG is earlier than 6b20-1.9.1-1ubuntu3
  • OR openjdk-6-dbg DPKG is earlier than 6b20-1.9.1-1ubuntu3
  • OR openjdk-6-jre-zero DPKG is earlier than 6b20-1.9.1-1ubuntu3
  • OR icedtea6-plugin DPKG is earlier than 6b20-1.9.1-1ubuntu3
  • OR Release section
  • Ubuntu 9.10 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND Packages section
  • openjdk-6-jre-lib DPKG is earlier than 6b18-1.8.2-4ubuntu1~9.10.1
  • OR openjdk-6-doc DPKG is earlier than 6b18-1.8.2-4ubuntu1~9.10.1
  • OR openjdk-6-source DPKG is earlier than 6b18-1.8.2-4ubuntu1~9.10.1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • openjdk-6-jre DPKG is earlier than 6b18-1.8.2-4ubuntu1~9.10.1
  • OR openjdk-6-jre-headless DPKG is earlier than 6b18-1.8.2-4ubuntu1~9.10.1
  • OR openjdk-6-demo DPKG is earlier than 6b18-1.8.2-4ubuntu1~9.10.1
  • OR openjdk-6-dbg DPKG is earlier than 6b18-1.8.2-4ubuntu1~9.10.1
  • OR openjdk-6-jdk DPKG is earlier than 6b18-1.8.2-4ubuntu1~9.10.1
  • OR icedtea6-plugin DPKG is earlier than 6b18-1.8.2-4ubuntu1~9.10.1
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is lpia
  • OR Installed architecture is powerpc
  • AND Packages section
  • icedtea-6-jre-cacao DPKG is earlier than 6b18-1.8.2-4ubuntu1~9.10.1
  • OR openjdk-6-jre-zero DPKG is earlier than 6b18-1.8.2-4ubuntu1~9.10.1
  • OR Release section
  • Ubuntu 10.04 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND Packages section
  • openjdk-6-jre-lib DPKG is earlier than 6b18-1.8.2-4ubuntu2
  • OR openjdk-6-doc DPKG is earlier than 6b18-1.8.2-4ubuntu2
  • OR openjdk-6-source DPKG is earlier than 6b18-1.8.2-4ubuntu2
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is powerpc
  • OR Installed architecture is amd64
  • OR Installed architecture is i386
  • AND Packages section
  • openjdk-6-jre DPKG is earlier than 6b18-1.8.2-4ubuntu2
  • OR openjdk-6-jre-headless DPKG is earlier than 6b18-1.8.2-4ubuntu2
  • OR openjdk-6-demo DPKG is earlier than 6b18-1.8.2-4ubuntu2
  • OR openjdk-6-dbg DPKG is earlier than 6b18-1.8.2-4ubuntu2
  • OR openjdk-6-jdk DPKG is earlier than 6b18-1.8.2-4ubuntu2
  • OR icedtea6-plugin DPKG is earlier than 6b18-1.8.2-4ubuntu2
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is powerpc
  • AND Packages section
  • icedtea-6-jre-cacao DPKG is earlier than 6b18-1.8.2-4ubuntu2
  • OR openjdk-6-jre-zero DPKG is earlier than 6b18-1.8.2-4ubuntu2
  • BACK