The IcedTea project provides a harness to build the source code from OpenJDK6 using Free Software build tools, along with additional features such as a PulseAudio sound driver and support for alternative virtual machines.
Credit:
The original article can be found at: http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-October/020556.html
The information has been provided by Elliott Baron ,Deepak Bhole ,Andrew John Hughes ,Omair Majid , Chris Phillips,Roman Kennke ,Pavel Tisnovsky,Mario Torre ,Jon VanAlten .
Vulnerable Systems:
* IcedTea6 1.10.10
* IcedTea6 1.11.5
Problem Description:
Multiple security issues were identified and fixed in OpenJDK (icedtea6):
* S6631398, CVE-2012-3216: FilePermission improved path checking
* S7093490: adjust package access in rmiregistry
* S7143535, CVE-2012-5068: ScriptEngine corrected permissions
* S7167656, CVE-2012-5077: Multiple Seeders are being created
* S7169884, CVE-2012-5073: LogManager checks do not work correctly for sub-types
* S7169888, CVE-2012-5075: Narrowing resource definitions in JMX RMI connector
* S7172522, CVE-2012-5072: Improve DomainCombiner checking
* S7186286, CVE-2012-5081: TLS implementation to better adhere to RFC
* S7189103, CVE-2012-5069: Executors needs to maintain state
* S7189490: More improvements to DomainCombiner checking
* S7189567, CVE-2012-5085: java net obselete protocol
* S7192975, CVE-2012-5071: Conditional usage check is wrong
* S7195194, CVE-2012-5084: Better data validation for Swing
* S7195917, CVE-2012-5086: XMLDecoder parsing at close-time should be improved
* S7195919, CVE-2012-5979: (sl) ServiceLoader can throw CCE without needing to create instance
* S7198296, CVE-2012-5089: Refactor classloader usage
* S7158800: Improve storage of symbol tables
* S7158801: Improve VM CompileOnly option
* S7158804: Improve config file parsing
* S7176337: Additional changes needed for 7158801 fix
* S7198606, CVE-2012-4416: Improve VM optimization
The updated packages provides icedtea6-1.11.5 which is not vulnerable to these issues.
Patch Availability:
http://icedtea.classpath.org/download/source/icedtea6-1.10.10.tar.gz
http://icedtea.classpath.org/download/source/icedtea6-1.11.5.tar.gz
CVE Information:
CVE-2012-3216
CVE-2012-5068
CVE-2012-5077
CVE-2012-5073
CVE-2012-5075
CVE-2012-5072
CVE-2012-5081
CVE-2012-5069
CVE-2012-5085
CVE-2012-5071
CVE-2012-5084
CVE-2012-5086
CVE-2012-5079
CVE-2012-5089
CVE-2012-4416
Disclosure Timeline:
Date : November 1, 2012
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by