Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple OpenJDK 6 vulnerabilities have been fixed.
Software Description:
- openjdk-6: Open Source Java implementation
- openjdk-6b18: Open Source Java implementation
Details:
It was discovered that a heap overflow in the AWT FileDialog.show()
method could allow an attacker to cause a denial of service through an
application crash or possibly execute arbitrary code. (CVE-2011-0815)
It was dicovered that integer overflows in the JPEGImageReader
readImage() function and the SunLayoutEngine nativeLayout() function
could allow an attacker to cause a denial of service through an
application crash or possibly execute arbitrary code. (CVE-2011-0822,
CVE-2011-0862)
It was discovered that memory corruption could occur when interpreting
bytecode in the HotSpot VM. This could allow an attacker to cause a
denial of service through an application crash or possibly execute
arbitrary code. (CVE-2011-0864)
It was discovered that the deserialization code allowed the creation
of mutable Signed...
The problem can be corrected by updating your system to the following package versions: Ubuntu 11.04: openjdk-6-jre 6b22-1.10.2-0ubuntu1~11.04.1 openjdk-6-jre-headless 6b22-1.10.2-0ubuntu1~11.04.1 openjdk-6-jre-lib 6b22-1.10.2-0ubuntu1~11.04.1 Ubuntu 10.10: icedtea6-plugin 6b20-1.9.8-0ubuntu1~10.10.1 openjdk-6-jre 6b20-1.9.8-0ubuntu1~10.10.1 openjdk-6-jre-headless 6b20-1.9.8-0ubuntu1~10.10.1 openjdk-6-jre-lib 6b20-1.9.8-0ubuntu1~10.10.1 Ubuntu 10.04 LTS: icedtea6-plugin 6b20-1.9.8-0ubuntu1~10.04.1 openjdk-6-jre 6b20-1.9.8-0ubuntu1~10.04.1 openjdk-6-jre-headless 6b20-1.9.8-0ubuntu1~10.04.1 openjdk-6-jre-lib 6b20-1.9.8-0ubuntu1~10.04.1 After a standard system update you need to restart any Java services, applications or applets to make all the necessary changes.
CVE-2011-0815, CVE-2011-0822, CVE-2011-0862, CVE-2011-0864,
CVE-2011-0865, CVE-2011-0867, CVE-2011-0868, CVE-2011-0869,
CVE-2011-0870, CVE-2011-0871, CVE-2011-0872
Get the latest Linux and open source security news straight to your inbox.