Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.120067
Category:Amazon Linux Local Security Checks
Title:Amazon Linux: Security Advisory (ALAS-2012-119)
Summary:The remote host is missing an update for the 'java-1.6.0-openjdk' package(s) announced via the ALAS-2012-119 advisory.
Description:Summary:
The remote host is missing an update for the 'java-1.6.0-openjdk' package(s) announced via the ALAS-2012-119 advisory.

Vulnerability Insight:
It was discovered that the Beans component in OpenJDK did not perform permission checks properly. An untrusted Java application or applet could use this flaw to use classes from restricted packages, allowing it to bypass Java sandbox restrictions. (CVE-2012-1682)

A hardening fix was applied to the AWT component in OpenJDK, removing functionality from the restricted SunToolkit class that was used in combination with other flaws to bypass Java sandbox restrictions. (CVE-2012-0547)

Affected Software/OS:
'java-1.6.0-openjdk' package(s) on Amazon Linux.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-0547
BugTraq ID: 55339
http://www.securityfocus.com/bid/55339
http://security.gentoo.org/glsa/glsa-201406-32.xml
HPdes Security Advisory: HPSBUX02824
https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03533078
HPdes Security Advisory: HPSBUX02825
http://marc.info/?l=bugtraq&m=135161897205627&w=2
HPdes Security Advisory: SSRT100970
HPdes Security Advisory: SSRT100974
RedHat Security Advisories: RHSA-2012:1222
http://rhn.redhat.com/errata/RHSA-2012-1222.html
RedHat Security Advisories: RHSA-2012:1225
http://rhn.redhat.com/errata/RHSA-2012-1225.html
RedHat Security Advisories: RHSA-2012:1392
http://rhn.redhat.com/errata/RHSA-2012-1392.html
RedHat Security Advisories: RHSA-2012:1466
http://rhn.redhat.com/errata/RHSA-2012-1466.html
RedHat Security Advisories: RHSA-2013:1455
http://rhn.redhat.com/errata/RHSA-2013-1455.html
RedHat Security Advisories: RHSA-2013:1456
http://rhn.redhat.com/errata/RHSA-2013-1456.html
http://secunia.com/advisories/51044
http://secunia.com/advisories/51141
http://secunia.com/advisories/51327
SuSE Security Announcement: SUSE-SU-2012:1148 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00006.html
SuSE Security Announcement: SUSE-SU-2012:1231 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.html
SuSE Security Announcement: openSUSE-SU-2012:1175 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00019.html
http://www.ubuntu.com/usn/USN-1553-1
Common Vulnerability Exposure (CVE) ID: CVE-2012-1682
http://marc.info/?l=bugtraq&m=135109152819176&w=2
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.