Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Ubuntu 11.10 USN-1263-2 Moderate: OpenJDK 6 TLS/SSL Issue

ubuntu
Calendar Grey January 24, 2012
Scroller Ubuntu
Addressing an SSL/TLS regression in OpenJDK 6 impacting various Ubuntu versions is vital for security. Users should apply the latest updates to avoid vulnerabilities.
USN-1263-1 caused a regression when using OpenJDK 6's SSL/TLS implementation.

Summary

USN-1263-1 caused a regression when using OpenJDK 6's SSL/TLS

implementation.

Software Description:

- openjdk-6: Open Source Java implementation

- openjdk-6b18: Open Source Java implementation

Details:

USN-1263-1 fixed vulnerabilities in OpenJDK 6. The upstream patch for

the chosen plaintext attack on the block-wise AES encryption algorithm

(CVE-2011-3389) introduced a regression that caused TLS/SSL connections

to fail when using certain algorithms. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Deepak Bhole discovered a flaw in the Same Origin Policy (SOP)

implementation in the IcedTea web browser plugin. This could allow a

remote attacker to open connections to certain hosts that should

not be permitted. (CVE-2011-3377)

Juliano Rizzo and Thai Duong discovered that the block-wise AES

encryption algorithm block-wise as used in TLS/SSL was vulnerable to

a chosen-plaintext attack. This could allow...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  icedtea-6-jre-cacao             6b23~pre11-0ubuntu1.11.10.1
  icedtea-6-jre-jamvm             6b23~pre11-0ubuntu1.11.10.1
  openjdk-6-jre                   6b23~pre11-0ubuntu1.11.10.1
  openjdk-6-jre-headless          6b23~pre11-0ubuntu1.11.10.1
  openjdk-6-jre-lib               6b23~pre11-0ubuntu1.11.10.1
  openjdk-6-jre-zero              6b23~pre11-0ubuntu1.11.10.1

Ubuntu 11.04:
  icedtea-6-jre-cacao             6b22-1.10.4-0ubuntu1~11.04.2
  icedtea-6-jre-jamvm             6b22-1.10.4-0ubuntu1~11.04.2
  openjdk-6-jre                   6b22-1.10.4-0ubuntu1~11.04.2
  openjdk-6-jre-headless          6b22-1.10.4-0ubuntu1~11.04.2
  openjdk-6-jre-lib               6b22-1.10.4-0ubuntu1~11.04.2
  openjdk-6-jre-zero              6b22-1.10.4-0ubuntu1~11.04.2

Ubuntu 10.10:
  icedtea-6-jre-cacao             6b20-1.9.10-0ubuntu1~10.10.3
  openjdk-6-jre                   6b20-1.9.10-0ubuntu1~10.10.3
  openjdk-6-jre-headless          6b20-1.9.10-0ubuntu1~10.10.3
  openjdk-6-jre-lib               6b20-1.9.10-0ubuntu1~10.10.3
  openjdk-6-jre-zero              6b20-1.9.10-0ubuntu1~10.10.3

Ubuntu 10.04 LTS:
  icedtea-6-jre-cacao             6b20-1.9.10-0ubuntu1~10.04.3
  openjdk-6-jre                   6b20-1.9.10-0ubuntu1~10.04.3
  openjdk-6-jre-headless          6b20-1.9.10-0ubuntu1~10.04.3
  openjdk-6-jre-lib               6b20-1.9.10-0ubuntu1~10.04.3
  openjdk-6-jre-zero              6b20-1.9.10-0ubuntu1~10.04.3

After a standard system update you need to restart any Java applications
or applets to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1263-2

https://ubuntu.com/security/notices/USN-1263-1

https://bugs.launchpad.net/ubuntu/+source/openjdk-6/+bug/891761

Severity
important
Lowest
Low
Medium
High
Critical

January 24, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.