Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 12.04 LTS: USN-1505-1 Critical: OpenJDK 6 Java Issues Advisory

ubuntu
Calendar Grey July 13, 2012
Scroller Ubuntu
Ubuntu Security Alert USN-1505-1 highlights significant flaws in OpenJDK 6 impacting various Ubuntu versions.
Several security issues were fixed in OpenJDK 6.

Summary

Several security issues were fixed in OpenJDK 6.

Software Description:

- openjdk-6: Open Source Java implementation

- icedtea-web: A web browser plugin to execute Java applets

Details:

It was discovered that multiple flaws existed in the CORBA (Common

Object Request Broker Architecture) implementation in OpenJDK. An

attacker could create a Java application or applet that used these

flaws to bypass Java sandbox restrictions or modify immutable object

data. (CVE-2012-1711, CVE-2012-1719)

It was discovered that multiple flaws existed in the OpenJDK font

manager's layout lookup implementation. A attacker could specially

craft a font file that could cause a denial of service through

crashing the JVM (Java Virtual Machine) or possibly execute arbitrary

code. (CVE-2012-1713)

It was discovered that the SynthLookAndFeel class from Swing in

OpenJDK did not properly prevent access to certain UI elements

from outside the current application context. An attacker could

...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  openjdk-6-jre                   6b24-1.11.3-1ubuntu0.12.04.1

Ubuntu 11.10:
  icedtea-6-plugin                1.2-2ubuntu0.11.10.1
  openjdk-6-jre                   6b24-1.11.3-1ubuntu0.11.10.1

Ubuntu 11.04:
  icedtea-6-plugin                1.2-2ubuntu0.11.04.1
  openjdk-6-jre                   6b24-1.11.3-1ubuntu0.11.04.1

Ubuntu 10.04 LTS:
  icedtea-6-plugin                1.2-2ubuntu0.10.04.1
  openjdk-6-jre                   6b24-1.11.3-1ubuntu0.10.04.1

This update uses a new upstream release, which includes additional
bug fixes. After a standard system update you need to restart any
Java applications or applets to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1505-1

CVE-2012-1711, CVE-2012-1713, CVE-2012-1716, CVE-2012-1717,

CVE-2012-1718, CVE-2012-1719, CVE-2012-1723, CVE-2012-1724,

CVE-2012-1725

Severity
critical
Lowest
Low
Medium
High
Critical

July 13, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.