Sun Java JDK / JRE / SDK Multiple Vulnerabilities
Last Update Date:
9 Jun 2011 11:30
Release Date:
9 Jun 2011
6602
Views
RISK: High Risk
TYPE: Operating Systems - Application Platforms
Multiple vulnerabilities have been identified in Sun Java, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), compromise a user's system, and compromise a vulnerable system.
- Errors in the 2D and Sound component may allow execution of arbitrary code in a client and server deployment via e.g untrusted applets or data sent to APIs through a web service.
- Errors in the AWT, Deployment, HotSpot, Swing and JRE component may allow execution of arbitrary code in a client deployment via e.g untrusted applets or Java Web Start applications.
- An error in the 2D component can be exploited to disclose certain data in a client and server deployment via e.g untrusted applets or data sent to APIs through a web service.
- An error in the Networking and SAAJ component can be exploited to disclose certain data in a client deployment via e.g untrusted applets or Java Web Start applications.
- An error in the NIO component can be exploited to cause a DoS in a server deployment via e.g. data sent to APIs through a web service.
- An error in the Deserialization component can be exploited to manipulate certain data in a client deployment via e.g untrusted applets or Java Web Start applications.
Impact
- Denial of Service
- Remote Code Execution
- Information Disclosure
- Data Manipulation
System / Technologies affected
- Sun Java JDK 1.5.x
- Sun Java JDK 1.6.x / 6.x
- Sun Java JRE 1.6.x / 6.x
- Sun Java SDK 1.4.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Vulnerability Identifier
- CVE-2011-0786
- CVE-2011-0788
- CVE-2011-0802
- CVE-2011-0814
- CVE-2011-0815
- CVE-2011-0817
- CVE-2011-0862
- CVE-2011-0863
- CVE-2011-0864
- CVE-2011-0865
- CVE-2011-0866
- CVE-2011-0867
- CVE-2011-0868
- CVE-2011-0869
- CVE-2011-0871
- CVE-2011-0872
- CVE-2011-0873
Source
Related Link
Share with