Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
172

Ubuntu 12.10: USN-1693-1 Critical: OpenJDK 7 Code Execution

OpenJDK 7 could be made to crash or run programs as your login if it opened a specially crafted Java applet.. =========================================================================Ubuntu Security Notice USN-1693-1 January 16, 2013 openjdk-7 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 Summary: OpenJDK 7 could be made to crash or run programs as your login if it opened a specially crafted Java applet. Software Description: - openjdk-7: Open Source Java implementation Details: It was discovered that OpenJDK 7's security mechanism could be bypassed via Java applets. If a user were tricked into opening a malicious website, a remote attacker could exploit this to perform arbitrary code execution as the user invoking the program. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: icedtea-7-jre-cacao 7u9-2.3.4-0ubuntu1.12.10.1 icedtea-7-jre-jamvm 7u9-2.3.4-0ubuntu1.12.10.1 openjdk-7-jre 7u9-2.3.4-0ubuntu1.12.10.1 openjdk-7-jre-headless 7u9-2.3.4-0ubuntu1.12.10.1 openjdk-7-jre-lib 7u9-2.3.4-0ubuntu1.12.10.1 openjdk-7-jre-zero 7u9-2.3.4-0ubuntu1.12.10.1 After a standard system update you need to restart your browser to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1693-1 CVE-2012-3174, CVE-2013-0422 Package Information: https://launchpad.net/ubuntu/+source/openjdk-7/7u9-2.3.4-0ubuntu1.12.10.1 . Ubuntu 12.10 is susceptible to vulnerabilities in OpenJDK 7 that may enable arbitrary code execution. Ensure your system is up to date for better security.. OpenJDK 7, Ubuntu 12.10, Java Applet, Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 16, 2013 Critical Ubuntu
172

Ubuntu 11.04 & 11.10 USN-1505-2 Critical: IcedTea-Web Regression Fix

USN 1505-1 introduced a regression in the IcedTea-Web Java web browserplugin that prevented it from working with the Chromium web browser.. =========================================================================Ubuntu Security Notice USN-1505-2 August 30, 2012 icedtea-web regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.10 - Ubuntu 11.04 Summary: USN 1505-1 introduced a regression in the IcedTea-Web Java web browser plugin that prevented it from working with the Chromium web browser. Software Description: - icedtea-web: A web browser plugin to execute Java applets Details: USN-1505-1 fixed vulnerabilities in OpenJDK 6. As part of the update, IcedTea-Web packages were upgraded to a new version. That upgrade introduced a regression which prevented the IcedTea-Web plugin from working with the Chromium web browser in Ubuntu 11.04 and Ubuntu 11.10. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that multiple flaws existed in the CORBA (Common Object Request Broker Architecture) implementation in OpenJDK. An attacker could create a Java application or applet that used these flaws to bypass Java sandbox restrictions or modify immutable object data. (CVE-2012-1711, CVE-2012-1719) It was discovered that multiple flaws existed in the OpenJDK font manager's layout lookup implementation. A attacker could specially craft a font file that could cause a denial of service through crashing the JVM (Java Virtual Machine) or possibly execute arbitrary code. (CVE-2012-1713) It was discovered that the SynthLookAndFeel class from Swing in OpenJDK did not properly prevent access to certain UI elements from outside the current application context. An attacker could create a Java application or applet that used this flaw to cause a denial of service through crashing the JVM or bypass Java sandbox restrictions.(CVE-2012-1716) It was discovered that OpenJDK runtime library classes could create temporary files with insecure permissions. A local attacker could use this to gain access to sensitive information. (CVE-2012-1717) It was discovered that OpenJDK did not handle CRLs (Certificate Revocation Lists) properly. A remote attacker could use this to gain access to sensitive information. (CVE-2012-1718) It was discovered that the OpenJDK HotSpot Virtual Machine did not properly verify the bytecode of the class to be executed. A remote attacker could create a Java application or applet that used this to cause a denial of service through crashing the JVM or bypass Java sandbox restrictions. (CVE-2012-1723, CVE-2012-1725) It was discovered that the OpenJDK XML (Extensible Markup Language) parser did not properly handle some XML documents. An attacker could create an XML document that caused a denial of service in a Java application or applet parsing the document. (CVE-2012-1724) As part of this update, the IcedTea web browser applet plugin was updated for Ubuntu 10.04 LTS, Ubuntu 11.04, and Ubuntu 11.10. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: icedtea-6-plugin 1.2-2ubuntu0.11.10.3 Ubuntu 11.04: icedtea-6-plugin 1.2-2ubuntu0.11.04.3 After a standard system update you need to restart your web browser to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1505-2 https://ubuntu.com/security/notices/USN-1505-1 https://bugs.launchpad.net/ubuntu/+source/icedtea-web/+bug/1025553 Package Information: https://launchpad.net/ubuntu/+source/icedtea-web/1.2-2ubuntu0.11.10.3 https://launchpad.net/ubuntu/+source/icedtea-web/1.2-2ubuntu0.11.04.3 . Ubuntu Security Announcement USN-1506-3 addresses a regression in IcedTea-Web impacting the Firefox browser.. IcedTea-Web, Ubuntu Update, Java Plugin, Security Fix, Web Browser. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Aug 30, 2012 Critical Ubuntu
98

Red Hat: RHSA-2008:0955-01 Critical: Java Applet Remote Threat

Updated java-1.4.2-ibm packages that fix several security issues are now available for Red Hat Enterprise Linux 3 Extras, Red Hat Enterprise Linux 4 Extras, and Red Hat Enterprise Linux 5 Supplementary. Multiple vulnerabilities with unsigned applets were reported. A remote attacker could misuse an unsigned applet to connect to localhost services running on the host running the applet. (CVE-2008-3104) . ==================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.4.2-ibm security update Advisory ID: RHSA-2008:0955-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://access.redhat.com/errata/RHSA-2008:0955.html Issue date: 2008-11-25 Keywords: Security CVE Names: CVE-2008-3104 CVE-2008-3112 CVE-2008-3113 CVE-2008-3114 ==================================================================== 1. Summary: Updated java-1.4.2-ibm packages that fix several security issues are now available for Red Hat Enterprise Linux 3 Extras, Red Hat Enterprise Linux 4 Extras, and Red Hat Enterprise Linux 5 Supplementary. This update has been rated as having critical security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 3 Extras - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 Extras - i386, x86_64 Red Hat Enterprise Linux ES version 3 Extras - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 Extras - i386, ia64, x86_64 Red Hat Enterprise Linux AS version 4 Extras - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 4 Extras - i386, x86_64 Red Hat Enterprise Linux ES version 4 Extras - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 Extras - i386, ia64, x86_64 RHEL Desktop Supplementary (v. 5 client) - i386, x86_64 RHEL Supplementary (v. 5 server) - i386, ia64, ppc, s390x, x86_64 3. Description: IBM's 1.4.2 SR12Java release includes the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit. Multiple vulnerabilities with unsigned applets were reported. A remote attacker could misuse an unsigned applet to connect to localhost services running on the host running the applet. (CVE-2008-3104) Two file processing vulnerabilities in Java Web Start were found. Using an untrusted Java Web Start application, a remote attacker was able to create or delete arbitrary files with the permissions of the user running the untrusted application. (CVE-2008-3112, CVE-2008-3113) A vulnerability in Java Web Start when processing untrusted applications was reported. An attacker was able to acquire sensitive information, such as the cache location. (CVE-2008-3114) All users of java-1.4.2-ibm are advised to upgrade to these updated packages, which contain IBM's 1.4.2 SR12 Java release which resolves these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 454601 - CVE-2008-3104 Java RE allows Same Origin Policy to be Bypassed (6687932) 454606 - CVE-2008-3112 Java Web Start, arbitrary file creation (6703909) 454607 - CVE-2008-3113 Java Web Start arbitrary file creation/deletion file with user permissions (6704077) 454608 - CVE-2008-3114 Java Web Start, untrusted application may determine Cache Location (6704074) 6. Package List: Red Hat Enterprise Linux AS version 3Extras: i386: java-1.4.2-ibm-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-plugin-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el3.i386.rpm ia64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el3.ia64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el3.ia64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el3.ia64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el3.ia64.rpm ppc: java-1.4.2-ibm-1.4.2.12-1jpp.1.el3.ppc.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el3.ppc.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el3.ppc.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el3.ppc.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el3.ppc.rpm s390: java-1.4.2-ibm-1.4.2.12-1jpp.1.el3.s390.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el3.s390.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el3.s390.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el3.s390.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el3.s390.rpm s390x: java-1.4.2-ibm-1.4.2.12-1jpp.1.el3.s390x.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el3.s390x.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el3.s390x.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el3.s390x.rpm x86_64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el3.x86_64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el3.x86_64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el3.x86_64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el3.x86_64.rpm Red Hat Desktop version 3 Extras: i386: java-1.4.2-ibm-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-plugin-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el3.i386.rpm x86_64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el3.x86_64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el3.x86_64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el3.x86_64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el3.x86_64.rpm Red Hat Enterprise Linux ES version 3Extras: i386: java-1.4.2-ibm-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-plugin-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el3.i386.rpm ia64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el3.ia64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el3.ia64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el3.ia64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el3.ia64.rpm x86_64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el3.x86_64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el3.x86_64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el3.x86_64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el3.x86_64.rpm Red Hat Enterprise Linux WS version 3 Extras: i386: java-1.4.2-ibm-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-plugin-1.4.2.12-1jpp.1.el3.i386.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el3.i386.rpm ia64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el3.ia64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el3.ia64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el3.ia64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el3.ia64.rpm x86_64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el3.x86_64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el3.x86_64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el3.x86_64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el3.x86_64.rpm Red Hat Enterprise Linux AS version 4Extras: i386: java-1.4.2-ibm-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-plugin-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el4.i386.rpm ia64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el4.ia64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el4.ia64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el4.ia64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el4.ia64.rpm ppc: java-1.4.2-ibm-1.4.2.12-1jpp.1.el4.ppc.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el4.ppc.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el4.ppc.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el4.ppc.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el4.ppc.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el4.ppc.rpm s390: java-1.4.2-ibm-1.4.2.12-1jpp.1.el4.s390.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el4.s390.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el4.s390.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el4.s390.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el4.s390.rpm s390x: java-1.4.2-ibm-1.4.2.12-1jpp.1.el4.s390x.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el4.s390x.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el4.s390x.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el4.s390x.rpm x86_64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el4.x86_64.rpm Red Hat Desktop version 4Extras: i386: java-1.4.2-ibm-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-plugin-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el4.i386.rpm x86_64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el4.x86_64.rpm Red Hat Enterprise Linux ES version 4 Extras: i386: java-1.4.2-ibm-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-plugin-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el4.i386.rpm ia64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el4.ia64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el4.ia64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el4.ia64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el4.ia64.rpm x86_64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el4.x86_64.rpm Red Hat Enterprise Linux WS version 4Extras: i386: java-1.4.2-ibm-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-plugin-1.4.2.12-1jpp.1.el4.i386.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el4.i386.rpm ia64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el4.ia64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el4.ia64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el4.ia64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el4.ia64.rpm x86_64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el4.x86_64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el4.x86_64.rpm RHEL Desktop Supplementary (v. 5 client): i386: java-1.4.2-ibm-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-plugin-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el5.i386.rpm x86_64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-1.4.2.12-1jpp.1.el5.x86_64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el5.x86_64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el5.x86_64.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el5.x86_64.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-plugin-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el5.x86_64.rpm RHEL Supplementary (v. 5server): i386: java-1.4.2-ibm-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-plugin-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el5.i386.rpm ia64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el5.ia64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el5.ia64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el5.ia64.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el5.ia64.rpm ppc: java-1.4.2-ibm-1.4.2.12-1jpp.1.el5.ppc.rpm java-1.4.2-ibm-1.4.2.12-1jpp.1.el5.ppc64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el5.ppc.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el5.ppc64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el5.ppc.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el5.ppc64.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el5.ppc.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el5.ppc64.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el5.ppc.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el5.ppc.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el5.ppc64.rpm s390x: java-1.4.2-ibm-1.4.2.12-1jpp.1.el5.s390.rpm java-1.4.2-ibm-1.4.2.12-1jpp.1.el5.s390x.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el5.s390.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el5.s390x.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el5.s390.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el5.s390x.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el5.s390.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el5.s390.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el5.s390x.rpm x86_64: java-1.4.2-ibm-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-1.4.2.12-1jpp.1.el5.x86_64.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-demo-1.4.2.12-1jpp.1.el5.x86_64.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-devel-1.4.2.12-1jpp.1.el5.x86_64.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-javacomm-1.4.2.12-1jpp.1.el5.x86_64.rpm java-1.4.2-ibm-jdbc-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-plugin-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el5.i386.rpm java-1.4.2-ibm-src-1.4.2.12-1jpp.1.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2008-3104 https://www.cve.org/CVERecord?id=CVE-2008-3112 https://www.cve.org/CVERecord?id=CVE-2008-3113 https://www.cve.org/CVERecord?id=CVE-2008-3114 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2008 Red Hat, Inc. . Essential security patch for java-1.4.2-ibm modules addresses various threats for Red Hat customers.. java security patch, red hat advisory, critical update, java issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 25, 2008 Critical Red Hat
91

Gentoo: 200705-20 Normal: Blackdown Java Applet Escalation Risks

The Blackdown JDK and the Blackdown JRE suffer from the multiple unspecified vulnerabilities that already affected the Sun JDK and JRE.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200705-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Blackdown Java: Applet privilege escalation Date: May 26, 2007 Bugs: #161835 ID: 200705-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= The Blackdown JDK and the Blackdown JRE suffer from the multiple unspecified vulnerabilities that already affected the Sun JDK and JRE. Background ========= Blackdown provides implementations of the Java Development Kit (JDK) and the Java Runtime Environment (JRE). Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-java/blackdown-jdk < 1.4.2.03-r14 > = 1.4.2.03-r14 2 dev-java/blackdown-jre < 1.4.2.03-r14 > = 1.4.2.03-r14 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Chris Evans has discovered multiple buffer overflows in the Sun JDK and the Sun JRE possibly related to various AWT and font layout functions. Tom Hawtin has discovered an unspecified vulnerability in the Sun JDK and the Sun JRE relating to unintended applet data access. He has also discovered multiple other unspecified vulnerabilities in the Sun JDK and the Sun JRE allowing unintended Java applet or applicationresource acquisition. Additionally, a memory corruption error has been found in the handling of GIF images with zero width field blocks. Impact ===== An attacker could entice a user to run a specially crafted Java applet or application that could read, write, or execute local files with the privileges of the user running the JVM, access data maintained in other Java applets, or escalate the privileges of the currently running Java applet or application allowing for unauthorized access to system resources. Workaround ========= Disable the "nsplugin" USE flag in order to prevent web applets from being run. Resolution ========= Since there is no fixed update from Blackdown and since the flaw only occurs in the applets, the "nsplugin" USE flag has been masked in the portage tree. Emerge the ebuild again in order to fix the vulnerability. Another solution is to switch to another Java implementation such as the Sun implementation (dev-java/sun-jdk and dev-java/sun-jre-bin). # emerge --sync # emerge --ask --oneshot --verbose "dev-java/blackdown-jdk" # emerge --ask --oneshot --verbose "dev-java/blackdown-jre" References ========= [ 1 ] CVE-2006-6731 https://www.cve.org/CVERecord?id=CVE-2006-6731 [ 2 ] CVE-2006-6736 https://www.cve.org/CVERecord?id=CVE-2006-6736 [ 3 ] CVE-2006-6737 https://www.cve.org/CVERecord?id=CVE-2006-6737 [ 4 ] CVE-2006-6745 https://www.cve.org/CVERecord?id=CVE-2006-6745 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200705-20 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this documentare licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . The GLSA 200705-20 advisory highlights vulnerabilities in Blackdown Java related to applet escalation, outlining risks and mitigation steps to enhance security. Blackdown Java, Gentoo Security, Applet Risks, Escalation Threats. . LinuxSecurity.com Team

Calendar%202 May 26, 2007 Gentoo
91

Gentoo: GLSA-200601-10 normal: Java Applet Privilege Escalation

Sun's and Blackdown's JDK or JRE may allow untrusted applets to elevate their privileges.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200601-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Sun and Blackdown Java: Applet privilege escalation Date: January 16, 2006 Bugs: #118114 ID: 200601-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Sun's and Blackdown's JDK or JRE may allow untrusted applets to elevate their privileges. Background ========= Sun and Blackdown both provide implementations of the Java Development Kit (JDK) and Java Runtime Environment (JRE). Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-java/sun-jdk < 1.4.2.09 > = 1.4.2.09 2 dev-java/sun-jre-bin < 1.4.2.09 > = 1.4.2.09 3 dev-java/blackdown-jdk < 1.4.2.03 > = 1.4.2.03 4 dev-java/blackdown-jre < 1.4.2.03 > = 1.4.2.03 ------------------------------------------------------------------- 4 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Adam Gowdiak discovered multiple vulnerabilities in the Java Runtime Environment's Reflection APIs that may allow untrusted applets to elevate privileges. Impact ===== A remote attacker could embed a malicious Java applet in a web page and entice a victim to view it. This applet can then bypass security restrictions and execute any command oraccess any file with the rights of the user running the web browser. Workaround ========= There are no known workarounds at this time. Resolution ========= All Sun JDK users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-java/sun-jdk-1.4.2.09" All Sun JRE users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-java/sun-jre-bin-1.4.2.09" All Blackdown JDK users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-java/blackdown-jdk-1.4.2.03" All Blackdown JRE users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-java/blackdown-jre-1.4.2.03" Note to SPARC and PPC users: There is no stable secure Blackdown Java for the SPARC or PPC architectures. Affected users on the PPC architecture should consider switching to the IBM Java packages (ibm-jdk-bin and ibm-jre-bin). Affected users on the SPARC should remove the package until a SPARC package is released. References ========= [ 1 ] CVE-2005-3905 https://www.cve.org/CVERecord?id=CVE-2005-3905 [ 2 ] CVE-2005-3906 https://www.cve.org/CVERecord?id=CVE-2005-3906 [ 3 ] Sun Security Alert ID 102003 [ 4 ] Blackdown Java-Linux Security Advisory Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200601-10 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alikelicense. https://creativecommons.org/licenses/by-sa/2.0/ . The BlueSky and RedMountain web widgets could allow unauthorized access, presenting moderate risk levels. It is advised to implement updates.. Java Applet Security, Gentoo Advisory, Privilege Escalation, System Upgrade, Java Security Patch. . LinuxSecurity.com Team

Calendar%202 Jan 16, 2006 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200