Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 11.04 LTS: USN-1373-2 Critical: OpenJDK 6 ARM Denial of Service

ubuntu
Calendar Grey March 1, 2012
Scroller Ubuntu
Numerous OpenJDK 6 security flaws addressed in Ubuntu for ARM architecture. Users advised to update for enhanced protection on vulnerable versions.
Multiple vulnerabilities in OpenJDK 6 for the ARM architecture have been fixed.

Summary

Multiple vulnerabilities in OpenJDK 6 for the ARM architecture have

been fixed.

Software Description:

- openjdk-6b18: Open Source Java implementation

Details:

USN 1373-1 fixed vulnerabilities in OpenJDK 6 in Ubuntu 10.04 LTS,

Ubuntu 10.10 and Ubuntu 11.04 for all architectures except for ARM

(armel). This provides the corresponding OpenJDK 6 update for use

with the ARM (armel) architecture in Ubuntu 10.04 LTS, Ubuntu 10.10

and Ubuntu 11.04.

Original advisory details:

It was discovered that the Java HttpServer class did not limit the

number of headers read from a HTTP request. A remote attacker could

cause a denial of service by sending special requests that trigger

hash collisions predictably. (CVE-2011-5035)

ATTENTION: this update changes previous Java HttpServer class behavior

by limiting the number of request headers to 200. This may be increased

by adjusting the sun.net.httpserver.maxReqHeaders property.

It was discovered that the Java...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  icedtea-6-jre-cacao             6b18-1.8.13-0ubuntu1~11.04.1
  icedtea-6-jre-jamvm             6b18-1.8.13-0ubuntu1~11.04.1
  openjdk-6-jre                   6b18-1.8.13-0ubuntu1~11.04.1
  openjdk-6-jre-headless          6b18-1.8.13-0ubuntu1~11.04.1
  openjdk-6-jre-zero              6b18-1.8.13-0ubuntu1~11.04.1

Ubuntu 10.10:
  icedtea-6-jre-cacao             6b18-1.8.13-0ubuntu1~10.10.1
  openjdk-6-jre                   6b18-1.8.13-0ubuntu1~10.10.1
  openjdk-6-jre-headless          6b18-1.8.13-0ubuntu1~10.10.1
  openjdk-6-jre-zero              6b18-1.8.13-0ubuntu1~10.10.1

Ubuntu 10.04 LTS:
  icedtea-6-jre-cacao             6b18-1.8.13-0ubuntu1~10.04.1
  openjdk-6-jre                   6b18-1.8.13-0ubuntu1~10.04.1
  openjdk-6-jre-headless          6b18-1.8.13-0ubuntu1~10.04.1
  openjdk-6-jre-zero              6b18-1.8.13-0ubuntu1~10.04.1

After a standard system update you need to restart any Java applications
or applets to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1373-2

https://ubuntu.com/security/notices/USN-1373-1

CVE-2011-3563, CVE-2011-5035, CVE-2012-0497, CVE-2012-0501,

CVE-2012-0502, CVE-2012-0503, CVE-2012-0505, CVE-2012-0506,

CVE-2012-0507

Severity
critical
Lowest
Low
Medium
High
Critical

March 01, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.