PT-2012-1238 · Oracle+4 · Java Runtime Environment+5
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Java Runtime Environment versions 5.0 Update 33 and earlier
Java Runtime Environment versions 6 Update 30 and earlier
Java Runtime Environment versions 7 Update 2 and earlier
Description
The issue is related to an unspecified vulnerability in the Java Runtime Environment component, allowing remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. This may be caused by the AtomicReferenceArray class implementation not ensuring that the array is of the Object[] type, potentially allowing attackers to cause a denial of service or bypass Java sandbox restrictions.
Recommendations
For Java Runtime Environment versions 5.0 Update 33 and earlier, update to a version later than Update 33 to resolve the issue.
For Java Runtime Environment versions 6 Update 30 and earlier, update to a version later than Update 30 to resolve the issue.
For Java Runtime Environment versions 7 Update 2 and earlier, update to a version later than Update 2 to resolve the issue.
As a temporary workaround, consider restricting access to the Concurrency component until a patch is available.
Exploit
Correção
DoS
Type Confusion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Centos
Hp-Ux
Java Platform
Java Runtime Environment
Red Hat
Suse