Oval Definition:oval:org.mitre.oval:def:13469
Revision Date:2014-06-23Version:20
Title:DSA-1769-1 openjdk-6 -- several
Description:Several vulnerabilities have been identified in OpenJDK, an implementation of the Java SE platform. Creation of large, temporary fonts could use up available disk space, leading to a denial of service condition. Several vulnerabilities existed in the embedded LittleCMS library, exploitable through crafted images: a memory leak, resulting in a denial of service condition, heap-based buffer overflows, potentially allowing arbitrary code execution, and a null-pointer dereference, leading to denial of service. The LDAP server implementation did not properly close sockets if an error was encountered, leading to a denial-of-service condition. The LDAP client implementation allowed malicious LDAP servers to execute arbitrary code on the client. The HTTP server implementation contained an unspecified denial of service vulnerability. Several issues in Java Web Start have been addressed. The Debian packages currently do not support Java Web Start, so these issues are not directly exploitable, but the relevant code has been updated nevertheless. For the stable distribution, these problems have been fixed in version 9.1+lenny2. We recommend that you upgrade your openjdk-6 packages.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2006-2426
CVE-2009-0581
CVE-2009-0723
CVE-2009-0733
CVE-2009-0793
CVE-2009-1093
CVE-2009-1094
CVE-2009-1095
CVE-2009-1096
CVE-2009-1097
CVE-2009-1098
CVE-2009-1101
DSA-1769-1
Platform(s):Debian GNU/Linux 5.0
Product(s):openjdk-6
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • openjdk-6-jre-lib DPKG is earlier than 6b11-9.1+lenny2
  • OR openjdk-6-doc DPKG is earlier than 6b11-9.1+lenny2
  • OR openjdk-6-source DPKG is earlier than 6b11-9.1+lenny2
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is powerpc
  • OR Installed architecture is i386
  • OR Installed architecture is mips
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is mipsel
  • AND Packages section
  • openjdk-6-jre-headless DPKG is earlier than 6b11-9.1+lenny2
  • OR openjdk-6-demo DPKG is earlier than 6b11-9.1+lenny2
  • OR openjdk-6-dbg DPKG is earlier than 6b11-9.1+lenny2
  • OR openjdk-6-jdk DPKG is earlier than 6b11-9.1+lenny2
  • OR openjdk-6-jre DPKG is earlier than 6b11-9.1+lenny2
  • BACK