Java has Huge Security Vulnerability, should be updated to 6update2
Bug #126059 reported by
VF
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
sun-java6 (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
See here: http://
as well as many other places.
It's not good to have packages with known huge security bugs in the repos, the average user who expects that Ubuntu will handle this for him will get bit hard.
To post a comment you must log in.
I'm going to set the Status to "Confirmed"; as per http:// sunsolve. sun.com/ search/ printfriendly. do?assetkey= 1-26-102934- 1
---
A buffer overflow vulnerability in the image parsing code in the Java Runtime Environment may allow an untrusted applet or application to elevate its privileges. For example, an applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet.
A second vulnerability may allow an untrusted applet or application to cause the Java Virtual Machine to hang.
Sun acknowledges, with thanks, Chris Evans of the Google Security Team, for bringing these issues to our attention.
These issues are also referenced in the following documents:
CVE-2007-2788 at http:// cve.mitre. org/cgi- bin/cvename. cgi?name= CVE-2007- 2788
CVE-2007-2789 at http:// cve.mitre. org/cgi- bin/cvename. cgi?name= CVE-2007- 2789
---