Oracle Java SE Multiple Vulnerabilities
Last Update Date:
15 Feb 2012 10:26
Release Date:
15 Feb 2012
5512
Views
RISK: High Risk
TYPE: Operating Systems - Application Platforms
Multiple vulnerabilities have been identified in Oracle Java SE, which can be exploited by attackers to execute arbitrary code, cause denial of service, and manipulate data.
- A remote user can send specially crafted data to execute arbitrary code on the target system or cause complete denial of service conditions. The Java 2D, deploy, and install components are affected. JavaFX is also affected.
- A remote user can partially access and modify data and partially deny service on the target system. The I18n and serialization components are affected.
- A remote user can partially access data and partially deny service on the target system. The AWT and sound components are affected.
- A remote user can cause partial denial of service conditions on the target system. The JRE component is affected.
- A remote user can partially modify data on the target system. The CORBA component is affected.
Impact
- Denial of Service
- Remote Code Execution
- Data Manipulation
System / Technologies affected
- Java SE 1.4.2_35 and prior
- Java SE 5.0 Update 33 and prior
- Java SE 6 Update 30 and prior
- Java SE 7 Update 2 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix.
http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html
Vulnerability Identifier
- CVE-2011-3563
- CVE-2012-0497
- CVE-2012-0498
- CVE-2012-0499
- CVE-2012-0500
- CVE-2012-0501
- CVE-2012-0502
- CVE-2012-0503
- CVE-2012-0504
- CVE-2012-0505
- CVE-2012-0506
- CVE-2012-0508
Source
Related Link
Share with