Skip to main content

Sun Java JDK / JRE / SDK Multiple Vulnerabilities

Last Update Date: 9 Jun 2011 11:30 Release Date: 9 Jun 2011 5767 Views

RISK: High Risk

TYPE: Operating Systems - Application Platforms

TYPE: Application Platforms

Multiple vulnerabilities have been identified in Sun Java, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), compromise a user's system, and compromise a vulnerable system.

  1. Errors in the 2D and Sound component may allow execution of arbitrary code in a client and server deployment via e.g untrusted applets or data sent to APIs through a web service.
  2. Errors in the AWT, Deployment, HotSpot, Swing and JRE component may allow execution of arbitrary code in a client deployment via e.g untrusted applets or Java Web Start applications.
  3. An error in the 2D component can be exploited to disclose certain data in a client and server deployment via e.g untrusted applets or data sent to APIs through a web service.
  4. An error in the Networking and SAAJ component can be exploited to disclose certain data in a client deployment via e.g untrusted applets or Java Web Start applications.
  5. An error in the NIO component can be exploited to cause a DoS in a server deployment via e.g. data sent to APIs through a web service.
  6. An error in the Deserialization component can be exploited to manipulate certain data in a client deployment via e.g untrusted applets or Java Web Start applications.

Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Sun Java JDK 1.5.x
  • Sun Java JDK 1.6.x / 6.x
  • Sun Java JRE 1.6.x / 6.x
  • Sun Java SDK 1.4.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link