Skip to main content

Oracle Sun Java JDK, JRE and SDK Multiple Vulnerabilities

Last Update Date: 25 Feb 2011 Release Date: 18 Feb 2011 6048 Views

RISK: High Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Multiple vulnerabilities have been identified in Oracle Sun Java JDK, JRE and SDK, which could be exploited by remote attackers or malicious users to manipulate or gain knowledge of sensitive information, bypass restrictions, cause a denial of service or compromise a vulnerable system. These issues are caused by errors in the Deployment, Sound, Swing, HotSpot, Install, JAXP, 2D, JDBC, Launcher, Networking, XML Digital Signature, and Security components.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Oracle Sun JDK version 6 Update 23 and prior
  • Oracle Sun JDK version 5.0 Update 27 and prior
  • Oracle Sun JRE version 6 Update 23 and prior
  • Oracle Sun JRE version 5.0 Update 27 and prior
  • Oracle Sun JRE version 1.4.2_29 and prior
  • Oracle Sun SDK version 1.4.2_29 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

 

Upgrade to fixed versions :

http://www.oracle.com/technetwork/topics/security/javacpufeb2011-304611.html


Vulnerability Identifier


Source


Related Link