Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 12.10: USN-1693-1 Critical: OpenJDK 7 Code Execution

ubuntu
Calendar Grey January 16, 2013
Scroller Ubuntu
Ubuntu 12.10 is susceptible to vulnerabilities in OpenJDK 7 that may enable arbitrary code execution. Ensure your system is up to date for better security.
OpenJDK 7 could be made to crash or run programs as your login if it opened a specially crafted Java applet.

Summary

OpenJDK 7 could be made to crash or run programs as your login if it

opened a specially crafted Java applet.

Software Description:

- openjdk-7: Open Source Java implementation

Details:

It was discovered that OpenJDK 7's security mechanism could be bypassed via

Java applets. If a user were tricked into opening a malicious website, a

remote attacker could exploit this to perform arbitrary code execution as

the user invoking the program.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  icedtea-7-jre-cacao             7u9-2.3.4-0ubuntu1.12.10.1
  icedtea-7-jre-jamvm             7u9-2.3.4-0ubuntu1.12.10.1
  openjdk-7-jre                   7u9-2.3.4-0ubuntu1.12.10.1
  openjdk-7-jre-headless          7u9-2.3.4-0ubuntu1.12.10.1
  openjdk-7-jre-lib               7u9-2.3.4-0ubuntu1.12.10.1
  openjdk-7-jre-zero              7u9-2.3.4-0ubuntu1.12.10.1

After a standard system update you need to restart your browser to make all
the necessary changes.

References

https://ubuntu.com/security/notices/USN-1693-1

CVE-2012-3174, CVE-2013-0422

Severity
critical
Lowest
Low
Medium
High
Critical

=========================================================================Ubuntu Security Notice USN-1693-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.