Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 12.04 LTS: USN-2124-1 Critical: OpenJDK 6 Security Issues

ubuntu
Calendar Grey February 27, 2014
Scroller Ubuntu
Remedies for various OpenJDK 6 security flaws impacting Ubuntu versions are outlined, targeting safety issues.
Several security issues were fixed in OpenJDK 6.

Summary

Several security issues were fixed in OpenJDK 6.

Software Description:

- openjdk-6: Open Source Java implementation

Details:

A vulnerability was discovered in the OpenJDK JRE related to information

disclosure and data integrity. An attacker could exploit this to expose

sensitive data over the network. (CVE-2014-0411)

Several vulnerabilities were discovered in the OpenJDK JRE related to

information disclosure, data integrity and availability. An attacker could

exploit these to cause a denial of service or expose sensitive data over

the network. (CVE-2013-5878, CVE-2013-5907, CVE-2014-0373, CVE-2014-0422,

CVE-2014-0428)

Two vulnerabilities were discovered in the OpenJDK JRE related to

information disclosure. An attacker could exploit these to expose sensitive

data over the network. (CVE-2013-5884, CVE-2014-0368)

Two vulnerabilities were discovered in the OpenJDK JRE related to

availability. An attacker could exploit these to cause a denial of service.

(C...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  icedtea-6-jre-cacao             6b30-1.13.1-1ubuntu2~0.12.04.1
  icedtea-6-jre-jamvm             6b30-1.13.1-1ubuntu2~0.12.04.1
  openjdk-6-jre                   6b30-1.13.1-1ubuntu2~0.12.04.1
  openjdk-6-jre-headless          6b30-1.13.1-1ubuntu2~0.12.04.1
  openjdk-6-jre-lib               6b30-1.13.1-1ubuntu2~0.12.04.1
  openjdk-6-jre-zero              6b30-1.13.1-1ubuntu2~0.12.04.1

Ubuntu 10.04 LTS:
  icedtea-6-jre-cacao             6b30-1.13.1-1ubuntu2~0.10.04.1
  openjdk-6-jre                   6b30-1.13.1-1ubuntu2~0.10.04.1
  openjdk-6-jre-headless          6b30-1.13.1-1ubuntu2~0.10.04.1
  openjdk-6-jre-lib               6b30-1.13.1-1ubuntu2~0.10.04.1
  openjdk-6-jre-zero              6b30-1.13.1-1ubuntu2~0.10.04.1

This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any Java
applications or applets to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2124-1

CVE-2013-5878, CVE-2013-5884, CVE-2013-5896, CVE-2013-5907,

CVE-2013-5910, CVE-2014-0368, CVE-2014-0373, CVE-2014-0376,

CVE-2014-0411, CVE-2014-0416, CVE-2014-0422, CVE-2014-0423,

CVE-2014-0428, https://bugs.launchpad.net/ubuntu/+source/openjdk-6/+bug/1283828

Severity
critical
Lowest
Low
Medium
High
Critical

=========================================================================Ubuntu Security Notice USN-2124-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.