PT-2011-1575 · Oracle+1 · Java Runtime Environment+2

Publicado

2011-02-17

·

Atualizado

2017-12-22

·

CVE-2010-4471

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Java Runtime Environment (JRE) versions 6 Update 23 and earlier Java Runtime Environment (JRE) versions 5.0 Update 27 and earlier
Description The issue allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to 2D. It is also claimed by a downstream vendor that this issue may be related to the exposure of system properties via vectors related to Font.createFont and exception text.
Recommendations For Java Runtime Environment (JRE) versions 6 Update 23 and earlier, update to a version later than Update 23. For Java Runtime Environment (JRE) versions 5.0 Update 27 and earlier, update to a version later than Update 27. As a temporary workaround, consider restricting the use of Java Web Start applications and Java applets from untrusted sources until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2010-4471
DSA-2224-1
RHSA-2011:0282
RHSA-2011:0357
RHSA-2011:0364
RHSA-2011:0880
RHSA-2011_0282
RHSA-2011_0357
RHSA-2011_0364

Produtos afetados

Java Platform
Java Runtime Environment
Red Hat