From 4f2d7949f03e1c198bc888f2d05f421d35c57e21 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 9 Oct 2017 18:53:29 +0100 Subject: reinit the tree, so we can have metadata --- metadata/glsa/glsa-200702-08.xml | 80 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 80 insertions(+) create mode 100644 metadata/glsa/glsa-200702-08.xml (limited to 'metadata/glsa/glsa-200702-08.xml') diff --git a/metadata/glsa/glsa-200702-08.xml b/metadata/glsa/glsa-200702-08.xml new file mode 100644 index 000000000000..02320aca96f3 --- /dev/null +++ b/metadata/glsa/glsa-200702-08.xml @@ -0,0 +1,80 @@ + + + + AMD64 x86 emulation Sun's J2SE Development Kit: Multiple vulnerabilities + + Multiple unspecified vulnerabilities have been identified in Sun Java + Development Kit (JDK) and Sun Java Runtime Environment (JRE). + + java + 2007-02-17 + 2009-05-28: 02 + 159547 + remote + + + 1.5.0.10 + 1.4.2.19 + 1.5.0.10 + + + +

+ The Sun Java Development Kit (JDK) and the Sun Java Runtime Environment + (JRE) provide the Sun Java platform. The x86 emulation Sun's J2SE + Development Kit for AMD64 contains a vulnerable version of Sun's JDK. +

+
+ +

+ Chris Evans has discovered multiple buffer overflows in Sun JDK and Sun + JRE possibly related to various AWT or font layout functions. Tom + Hawtin has discovered an unspecified vulnerability in Sun JDK and Sun + JRE relating to unintended applet data access. He has also discovered + multiple other unspecified vulnerabilities in Sun JDK and Sun JRE + allowing unintended Java applet or application resource acquisition. + Additionally, a memory corruption error has been found in the handling + of GIF images with zero width field blocks. +

+
+ +

+ An attacker could entice a user to run a specially crafted Java applet + or application that could read, write, or execute local files with the + privileges of the user running the JVM, access data maintained in other + Java applets, or escalate the privileges of the currently running Java + applet or application allowing for unauthorized access to system + resources. +

+
+ +

+ There is no known workaround at this time. +

+
+ +

+ All AMD64 x86 emulation Sun's J2SE Development Kit users should upgrade + to the latest version: +

+ + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-emulation/emul-linux-x86-java-1.5.0.10" +
+ + CVE-2006-6731 + CVE-2006-6736 + CVE-2006-6737 + CVE-2006-6745 + CVE-2007-0243 + + + falco + + + falco + + + falco + +
-- cgit v1.2.3