Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Ubuntu 11.10: 1373-1 Critical: OpenJDK 6 DoS Threats Summary

ubuntu
Calendar Grey February 24, 2012
Scroller Ubuntu
Uncover essential patches for several OpenJDK 6 security flaws affecting Ubuntu platforms and find out how to safeguard them.
Multiple OpenJDK 6 vulnerabilities have been fixed.

Summary

Multiple OpenJDK 6 vulnerabilities have been fixed.

Software Description:

- openjdk-6: Open Source Java implementation

Details:

It was discovered that the Java HttpServer class did not limit the

number of headers read from a HTTP request. A remote attacker could

cause a denial of service by sending special requests that trigger

hash collisions predictably. (CVE-2011-5035)

ATTENTION: this update changes previous Java HttpServer class behavior

by limiting the number of request headers to 200. This may be increased

by adjusting the sun.net.httpserver.maxReqHeaders property.

It was discovered that the Java Sound component did not properly

check buffer boundaries. A remote attacker could use this to cause

a denial of service or view confidential data. (CVE-2011-3563)

It was discovered that the Java2D implementation does not properly

check graphics rendering objects before passing them to the native

renderer. A remote attacker could use this to cause a denial of

service or to bypas...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  icedtea-6-jre-cacao             6b23~pre11-0ubuntu1.11.10.2
  icedtea-6-jre-jamvm             6b23~pre11-0ubuntu1.11.10.2
  openjdk-6-jre                   6b23~pre11-0ubuntu1.11.10.2
  openjdk-6-jre-headless          6b23~pre11-0ubuntu1.11.10.2
  openjdk-6-jre-lib               6b23~pre11-0ubuntu1.11.10.2
  openjdk-6-jre-zero              6b23~pre11-0ubuntu1.11.10.2

Ubuntu 11.04:
  icedtea-6-jre-cacao             6b22-1.10.6-0ubuntu1
  icedtea-6-jre-jamvm             6b22-1.10.6-0ubuntu1
  openjdk-6-jre                   6b22-1.10.6-0ubuntu1
  openjdk-6-jre-headless          6b22-1.10.6-0ubuntu1
  openjdk-6-jre-lib               6b22-1.10.6-0ubuntu1
  openjdk-6-jre-zero              6b22-1.10.6-0ubuntu1

Ubuntu 10.10:
  icedtea-6-jre-cacao             6b20-1.9.13-0ubuntu1~10.10.1
  openjdk-6-jre                   6b20-1.9.13-0ubuntu1~10.10.1
  openjdk-6-jre-headless          6b20-1.9.13-0ubuntu1~10.10.1
  openjdk-6-jre-lib               6b20-1.9.13-0ubuntu1~10.10.1
  openjdk-6-jre-zero              6b20-1.9.13-0ubuntu1~10.10.1

Ubuntu 10.04 LTS:
  icedtea-6-jre-cacao             6b20-1.9.13-0ubuntu1~10.04.1
  openjdk-6-jre                   6b20-1.9.13-0ubuntu1~10.04.1
  openjdk-6-jre-headless          6b20-1.9.13-0ubuntu1~10.04.1
  openjdk-6-jre-lib               6b20-1.9.13-0ubuntu1~10.04.1
  openjdk-6-jre-zero              6b20-1.9.13-0ubuntu1~10.04.1

After a standard system update you need to restart any Java applications
or applets to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1373-1

CVE-2011-3563, CVE-2011-5035, CVE-2012-0497, CVE-2012-0501,

CVE-2012-0502, CVE-2012-0503, CVE-2012-0505, CVE-2012-0506,

CVE-2012-0507

Severity
critical
Lowest
Low
Medium
High
Critical

February 24, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.