Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-0507

Опубликовано: 07 июн. 2012
Источник: ubuntu
Приоритет: medium
CVSS2: 10
CVSS3: 9.8

Описание

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

РелизСтатусПримечание
devel

not-affected

hardy

DNE

lucid

not-affected

maverick

DNE

natty

not-affected

oneiric

not-affected

precise

not-affected

quantal

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

6b24-1.11.1-0ubuntu1
hardy

released

6b27-1.12.3-0ubuntu1~08.04.1
lucid

released

6b20-1.9.13-0ubuntu1~10.04.1
maverick

released

6b20-1.9.13-0ubuntu1~10.10.1
natty

released

6b22-1.10.6-0ubuntu1
oneiric

released

6b23~pre11-0ubuntu1.11.10.2
precise

not-affected

6b24-1.11.1-0ubuntu1
quantal

not-affected

6b24-1.11.1-0ubuntu1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

released

6b18-1.8.13-0ubuntu1~10.04.1
maverick

released

6b18-1.8.13-0ubuntu1~10.10.1
natty

released

6b18-1.8.13-0ubuntu1~11.04.1
oneiric

ignored

end of life
precise

DNE

quantal

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

7~u3-2.1-1ubuntu1
hardy

DNE

lucid

DNE

maverick

DNE

natty

DNE

oneiric

released

7u9-2.3.3-0ubuntu1~11.10.1
precise

not-affected

7~u3-2.1-1ubuntu1
quantal

not-affected

7~u3-2.1-1ubuntu1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

ignored

end of life
lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

precise

DNE

quantal

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

ignored

end of life
lucid

DNE

removed from archive
maverick

DNE

removed from archive
natty

DNE

removed from archive
oneiric

DNE

precise

DNE

quantal

DNE

upstream

needs-triage

Показывать по

10 Critical

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

redhat
больше 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

CVSS3: 9.8
nvd
около 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

CVSS3: 9.8
debian
около 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) compon ...

CVSS3: 9.8
github
больше 3 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

CVSS3: 10
fstec
больше 13 лет назад

Уязвимость реализации класса AtomicReferenceArray компонента Concurrency программной платформы Java Runtime Environment, позволяющая нарушителю вызвать отказ в обслуживании

10 Critical

CVSS2

9.8 Critical

CVSS3