PT-2012-1238 · Oracle+4 · Java Runtime Environment+5

Tomas Hoger

·

Published

2012-02-09

·

Updated

2025-04-03

·

CVE-2012-0507

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Java Runtime Environment versions 5.0 Update 33 and earlier Java Runtime Environment versions 6 Update 30 and earlier Java Runtime Environment versions 7 Update 2 and earlier
Description The issue is related to an unspecified vulnerability in the Java Runtime Environment component, allowing remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. This may be caused by the AtomicReferenceArray class implementation not ensuring that the array is of the Object[] type, potentially allowing attackers to cause a denial of service or bypass Java sandbox restrictions.
Recommendations For Java Runtime Environment versions 5.0 Update 33 and earlier, update to a version later than Update 33 to resolve the issue. For Java Runtime Environment versions 6 Update 30 and earlier, update to a version later than Update 30 to resolve the issue. For Java Runtime Environment versions 7 Update 2 and earlier, update to a version later than Update 2 to resolve the issue. As a temporary workaround, consider restricting access to the Concurrency component until a patch is available.

Exploit

Fix

DoS

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2022-04096
CESA-2012_0135
CVE-2012-0507
DSA-2420-1
HPSBUX02757
HPSBUX02760
HPSBUX02784
RHSA-2012:0135
RHSA-2012:0139
RHSA-2012:0322
RHSA-2012:0508
RHSA-2012:0514
RHSA-2012_0135
RHSA-2012_0139
RHSA-2012_0322
RHSA-2012_0508
RHSA-2012_0514
RHSA-2013:1455

Affected Products

Centos
Hp-Ux
Java Platform
Java Runtime Environment
Red Hat
Suse