Описание
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | |
hardy | DNE | |
lucid | not-affected | |
maverick | DNE | |
natty | not-affected | |
oneiric | not-affected | |
precise | not-affected | |
quantal | not-affected | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 6b24-1.11.1-0ubuntu1 |
hardy | released | 6b27-1.12.3-0ubuntu1~08.04.1 |
lucid | released | 6b20-1.9.13-0ubuntu1~10.04.1 |
maverick | released | 6b20-1.9.13-0ubuntu1~10.10.1 |
natty | released | 6b22-1.10.6-0ubuntu1 |
oneiric | released | 6b23~pre11-0ubuntu1.11.10.2 |
precise | not-affected | 6b24-1.11.1-0ubuntu1 |
quantal | not-affected | 6b24-1.11.1-0ubuntu1 |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | DNE | |
lucid | released | 6b18-1.8.13-0ubuntu1~10.04.1 |
maverick | released | 6b18-1.8.13-0ubuntu1~10.10.1 |
natty | released | 6b18-1.8.13-0ubuntu1~11.04.1 |
oneiric | ignored | end of life |
precise | DNE | |
quantal | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 7~u3-2.1-1ubuntu1 |
hardy | DNE | |
lucid | DNE | |
maverick | DNE | |
natty | DNE | |
oneiric | released | 7u9-2.3.3-0ubuntu1~11.10.1 |
precise | not-affected | 7~u3-2.1-1ubuntu1 |
quantal | not-affected | 7~u3-2.1-1ubuntu1 |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | ignored | end of life |
lucid | DNE | |
maverick | DNE | |
natty | DNE | |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | ignored | end of life |
lucid | DNE | removed from archive |
maverick | DNE | removed from archive |
natty | DNE | removed from archive |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
upstream | needs-triage |
Показывать по
10 Critical
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
Unspecified vulnerability in the Java Runtime Environment (JRE) compon ...
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
Уязвимость реализации класса AtomicReferenceArray компонента Concurrency программной платформы Java Runtime Environment, позволяющая нарушителю вызвать отказ в обслуживании
10 Critical
CVSS2
9.8 Critical
CVSS3