Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.63748
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-748-1)
Summary:The remote host is missing an update for the 'openjdk-6' package(s) announced via the USN-748-1 advisory.
Description:Summary:
The remote host is missing an update for the 'openjdk-6' package(s) announced via the USN-748-1 advisory.

Vulnerability Insight:
It was discovered that font creation could leak temporary files.
If a user were tricked into loading a malicious program or applet,
a remote attacker could consume disk space, leading to a denial of
service. (CVE-2006-2426, CVE-2009-1100)

It was discovered that the lightweight HttpServer did not correctly close
files on dataless connections. A remote attacker could send specially
crafted requests, leading to a denial of service. (CVE-2009-1101)

The Java Runtime Environment did not correctly validate certain generated
code. If a user were tricked into running a malicious applet a remote
attacker could execute arbitrary code. (CVE-2009-1102)

It was discovered that LDAP connections did not close correctly.
A remote attacker could send specially crafted requests, leading to a
denial of service. (CVE-2009-1093)

Java LDAP routines did not unserialize certain data correctly. A remote
attacker could send specially crafted requests that could lead to
arbitrary code execution. (CVE-2009-1094)

Java did not correctly check certain JAR headers. If a user or
automated system were tricked into processing a malicious JAR file,
a remote attacker could crash the application, leading to a denial of
service. (CVE-2009-1095, CVE-2009-1096)

It was discovered that PNG and GIF decoding in Java could lead to memory
corruption. If a user or automated system were tricked into processing
a specially crafted image, a remote attacker could crash the application,
leading to a denial of service. (CVE-2009-1097, CVE-2009-1098)

Affected Software/OS:
'openjdk-6' package(s) on Ubuntu 8.10.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-2426
BugTraq ID: 17981
http://www.securityfocus.com/bid/17981
Bugtraq: 20060514 JDK 1.4.2_11, 1.5.0_06, unsigned applets consuming all free harddisk space (Google Search)
http://www.securityfocus.com/archive/1/434001/100/0/threaded
Debian Security Information: DSA-1769 (Google Search)
http://www.debian.org/security/2009/dsa-1769
http://www.mandriva.com/security/advisories?name=MDVSA-2009:137
http://www.mandriva.com/security/advisories?name=MDVSA-2009:162
http://www.illegalaccess.org/exploit/FullDiskApplet.html
http://www.osvdb.org/25561
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10609
RedHat Security Advisories: RHSA-2009:0377
https://rhn.redhat.com/errata/RHSA-2009-0377.html
http://www.redhat.com/support/errata/RHSA-2009-0392.html
http://www.redhat.com/support/errata/RHSA-2009-0394.html
http://secunia.com/advisories/20132
http://secunia.com/advisories/20457
http://secunia.com/advisories/34489
http://secunia.com/advisories/34495
http://secunia.com/advisories/34496
http://secunia.com/advisories/34632
http://secunia.com/advisories/34675
http://securityreason.com/securityalert/909
SuSE Security Announcement: SUSE-SR:2006:012 (Google Search)
http://www.novell.com/linux/security/advisories/2006-06-02.html
http://www.ubuntu.com/usn/usn-748-1
http://www.vupen.com/english/advisories/2006/1824
XForce ISS Database: sun-java-fontcreatefont-dos(26493)
https://exchange.xforce.ibmcloud.com/vulnerabilities/26493
Common Vulnerability Exposure (CVE) ID: CVE-2009-1093
BugTraq ID: 34240
http://www.securityfocus.com/bid/34240
Bugtraq: 20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components (Google Search)
http://www.securityfocus.com/archive/1/507985/100/0/threaded
http://security.gentoo.org/glsa/glsa-200911-02.xml
HPdes Security Advisory: HPSBMA02429
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133
HPdes Security Advisory: HPSBUX02429
http://marc.info/?l=bugtraq&m=124344236532162&w=2
HPdes Security Advisory: SSRT090058
http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-19-1
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11343
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6676
http://www.redhat.com/support/errata/RHSA-2009-1038.html
RedHat Security Advisories: RHSA-2009:1198
https://rhn.redhat.com/errata/RHSA-2009-1198.html
http://www.securitytracker.com/id?1021893
http://secunia.com/advisories/35156
http://secunia.com/advisories/35223
http://secunia.com/advisories/35255
http://secunia.com/advisories/35416
http://secunia.com/advisories/35776
http://secunia.com/advisories/36185
http://secunia.com/advisories/37386
http://secunia.com/advisories/37460
http://sunsolve.sun.com/search/document.do?assetkey=1-66-254569-1
SuSE Security Announcement: SUSE-SA:2009:016 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html
SuSE Security Announcement: SUSE-SA:2009:029 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html
SuSE Security Announcement: SUSE-SA:2009:036 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html
SuSE Security Announcement: SUSE-SR:2009:011 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html
http://www.vupen.com/english/advisories/2009/1426
http://www.vupen.com/english/advisories/2009/3316
Common Vulnerability Exposure (CVE) ID: CVE-2009-1094
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11064
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6598
http://www.vupen.com/english/advisories/2009/1900
Common Vulnerability Exposure (CVE) ID: CVE-2009-1095
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=781
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10124
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6643
http://www.securitytracker.com/id?1021894
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020225.1-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-254570-1
Common Vulnerability Exposure (CVE) ID: CVE-2009-1096
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6659
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8844
Common Vulnerability Exposure (CVE) ID: CVE-2009-1097
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=779
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=780
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11241
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6288
http://www.securitytracker.com/id?1021913
http://sunsolve.sun.com/search/document.do?assetkey=1-26-254571-1
XForce ISS Database: jre-gif-file-bo(49475)
https://exchange.xforce.ibmcloud.com/vulnerabilities/49475
Common Vulnerability Exposure (CVE) ID: CVE-2009-1098
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6008
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9956
Common Vulnerability Exposure (CVE) ID: CVE-2009-1100
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6224
http://www.securitytracker.com/id?1021917
http://sunsolve.sun.com/search/document.do?assetkey=1-66-254608-1
Common Vulnerability Exposure (CVE) ID: CVE-2009-1101
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10152
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6412
http://www.securitytracker.com/id?1021918
http://sunsolve.sun.com/search/document.do?assetkey=1-66-254609-1
Common Vulnerability Exposure (CVE) ID: CVE-2009-1102
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10300
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6722
http://www.securitytracker.com/id?1021919
http://sunsolve.sun.com/search/document.do?assetkey=1-66-254610-1
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.