PT-2012-1238 · Oracle+4 · Java Runtime Environment+5

·

CVE-2012-0507

·

Publicado

2012-02-09

·

Atualizado

2025-04-03

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Java Runtime Environment versions 5.0 Update 33 and earlier Java Runtime Environment versions 6 Update 30 and earlier Java Runtime Environment versions 7 Update 2 and earlier
Description The issue is related to an unspecified vulnerability in the Java Runtime Environment component, allowing remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. This may be caused by the AtomicReferenceArray class implementation not ensuring that the array is of the Object[] type, potentially allowing attackers to cause a denial of service or bypass Java sandbox restrictions.
Recommendations For Java Runtime Environment versions 5.0 Update 33 and earlier, update to a version later than Update 33 to resolve the issue. For Java Runtime Environment versions 6 Update 30 and earlier, update to a version later than Update 30 to resolve the issue. For Java Runtime Environment versions 7 Update 2 and earlier, update to a version later than Update 2 to resolve the issue. As a temporary workaround, consider restricting access to the Concurrency component until a patch is available.

Exploit

Correção

DoS

Type Confusion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-04096
CESA-2012_0135
CVE-2012-0507
DSA-2420-1
HPSBUX02757
HPSBUX02760
HPSBUX02784
RHSA-2012:0135
RHSA-2012:0139
RHSA-2012:0322
RHSA-2012:0508
RHSA-2012:0514
RHSA-2012_0135
RHSA-2012_0139
RHSA-2012_0322
RHSA-2012_0508
RHSA-2012_0514
RHSA-2013:1455

Produtos afetados

Centos
Hp-Ux
Java Platform
Java Runtime Environment
Red Hat
Suse