Oracle Sun Java JDK, JRE and SDK Multiple Vulnerabilities
RISK: High Risk
TYPE: Clients - Productivity Products
Multiple vulnerabilities have been identified in Oracle Sun Java JDK, JRE and SDK, which could be exploited by remote attackers or malicious users to manipulate or gain knowledge of sensitive information, bypass restrictions, cause a denial of service or compromise a vulnerable system. These issues are caused by errors in the Deployment, Sound, Swing, HotSpot, Install, JAXP, 2D, JDBC, Launcher, Networking, XML Digital Signature, and Security components.
Impact
- Denial of Service
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- Oracle Sun JDK version 6 Update 23 and prior
- Oracle Sun JDK version 5.0 Update 27 and prior
- Oracle Sun JRE version 6 Update 23 and prior
- Oracle Sun JRE version 5.0 Update 27 and prior
- Oracle Sun JRE version 1.4.2_29 and prior
- Oracle Sun SDK version 1.4.2_29 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Upgrade to fixed versions :
http://www.oracle.com/technetwork/topics/security/javacpufeb2011-304611.html
Vulnerability Identifier
- CVE-2010-4422
- CVE-2010-4447
- CVE-2010-4448
- CVE-2010-4450
- CVE-2010-4451
- CVE-2010-4452
- CVE-2010-4454
- CVE-2010-4462
- CVE-2010-4463
- CVE-2010-4465
- CVE-2010-4466
- CVE-2010-4467
- CVE-2010-4468
- CVE-2010-4469
- CVE-2010-4470
- CVE-2010-4471
- CVE-2010-4472
- CVE-2010-4473
- CVE-2010-4474
- CVE-2010-4475
- CVE-2010-4476
Source
Related Link
Share with