OpenJDK IndexColorModel double-free (6925710)
Published Oct 19, 2010
10.0
HIGHCVSS 2.0
EPSS 7.10%
Description
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this is a double free vulnerability in IndexColorModel that allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.
Affected products
No data.
Configuration 1
- ≤ 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
Configuration 2
- ≤ 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
Configuration 3
- ≤ 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
Configuration 4
- ≤ 1.4.2_27
- 1.4.2
- 1.4.2_1
- 1.4.2_02
- 1.4.2_3
- 1.4.2_4
- 1.4.2_5
- 1.4.2_6
- 1.4.2_7
- 1.4.2_8
- 1.4.2_9
- 1.4.2_10
- 1.4.2_11
- 1.4.2_12
- 1.4.2_13
- 1.4.2_14
- 1.4.2_15
- 1.4.2_16
- 1.4.2_17
- 1.4.2_18
- 1.4.2_19
- 1.4.2_20
- 1.4.2_21
- 1.4.2_22
- 1.4.2_23
- 1.4.2_24
- 1.4.2_25
- 1.4.2_26
Configuration 5
- ≤ 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
Configuration 6
- ≤ 1.4.2_27
- 1.4.2
- 1.4.2_1
- 1.4.2_2
- 1.4.2_3
- 1.4.2_4
- 1.4.2_5
- 1.4.2_6
- 1.4.2_7
- 1.4.2_8
- 1.4.2_9
- 1.4.2_10
- 1.4.2_11
- 1.4.2_12
- 1.4.2_13
- 1.4.2_14
- 1.4.2_15
- 1.4.2_16
- 1.4.2_17
- 1.4.2_18
- 1.4.2_19
- 1.4.2_20
- 1.4.2_21
- 1.4.2_22
- 1.4.2_23
- 1.4.2_24
- 1.4.2_25
- 1.4.2_26
Configuration 7
- ≤ 1.3.1_28
- 1.3.0
- 1.3.0_01
- 1.3.0_02
- 1.3.0_03
- 1.3.0_04
- 1.3.0_05
- 1.3.1
- 1.3.1_01
- 1.3.1_01a
- 1.3.1_02
- 1.3.1_03
- 1.3.1_04
- 1.3.1_05
- 1.3.1_06
- 1.3.1_07
- 1.3.1_08
- 1.3.1_09
- 1.3.1_10
- 1.3.1_11
- 1.3.1_12
- 1.3.1_13
- 1.3.1_14
- 1.3.1_15
- 1.3.1_16
- 1.3.1_17
- 1.3.1_18
- 1.3.1_19
- 1.3.1_20
- 1.3.1_21
- 1.3.1_22
- 1.3.1_23
- 1.3.1_24
- 1.3.1_25
- 1.3.1_26
- 1.3.1_27
Configuration 8
- ≤ 1.3.1_28
- 1.3.0
- 1.3.0
- 1.3.0
- 1.3.0
- 1.3.0
- 1.3.0
- 1.3.1
- 1.3.1
- 1.3.1
- 1.3.1_2
- 1.3.1_03
- 1.3.1_04
- 1.3.1_05
- 1.3.1_06
- 1.3.1_07
- 1.3.1_08
- 1.3.1_09
- 1.3.1_10
- 1.3.1_11
- 1.3.1_12
- 1.3.1_13
- 1.3.1_14
- 1.3.1_15
- 1.3.1_16
- 1.3.1_17
- 1.3.1_18
- 1.3.1_19
- 1.3.1_20
- 1.3.1_21
- 1.3.1_22
- 1.3.1_23
- 1.3.1_24
- 1.3.1_25
- 1.3.1_26
- 1.3.1_27
Configuration 9
- ≤ 1.3.1_28
- 1.3.0
- 1.3.0_01
- 1.3.0_02
- 1.3.0_03
- 1.3.0_04
- 1.3.0_05
- 1.3.1
- 1.3.1_01
- 1.3.1_01a
- 1.3.1_02
- 1.3.1_03
- 1.3.1_04
- 1.3.1_05
- 1.3.1_06
- 1.3.1_07
- 1.3.1_08
- 1.3.1_09
- 1.3.1_10
- 1.3.1_11
- 1.3.1_12
- 1.3.1_13
- 1.3.1_14
- 1.3.1_15
- 1.3.1_16
- 1.3.1_17
- 1.3.1_18
- 1.3.1_19
- 1.3.1_20
- 1.3.1_21
- 1.3.1_22
- 1.3.1_23
- 1.3.1_24
- 1.3.1_25
- 1.3.1_26
- 1.3.1_27
No data.
Extras for RHEL 3
java-1.4.2-ibm-0:1.4.2.13.6-1jpp.3.el3
Fixed · RHSA-2010:0786
Extras for RHEL 4
java-1.4.2-ibm-0:1.4.2.13.6-1jpp.2.el4
Fixed · RHSA-2010:0786
Extras for RHEL 4
java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el4
Fixed · RHSA-2010:0807
Extras for RHEL 4
java-1.6.0-ibm-1:1.6.0.9.0-1jpp.3.el4
Fixed · RHSA-2010:0987
Extras for RHEL 4
java-1.6.0-sun-1:1.6.0.22-1jpp.1.el4
Fixed · RHSA-2010:0770
RHEL 4 for SAP
java-1.4.2-ibm-sap-0:1.4.2.13.6.sap-1jpp.1.el4_8
Fixed · RHSA-2010:0986
RHEL 5 for SAP
java-1.4.2-ibm-sap-0:1.4.2.13.6.sap-1jpp.1.el5
Fixed · RHSA-2010:0986
Red Hat Enterprise Linux 5
java-1.6.0-openjdk-1:1.6.0.0-1.16.b17.el5
Fixed · RHSA-2010:0768
Red Hat Enterprise Linux 6
java-1.6.0-openjdk-1:1.6.0.0-1.31.b17.el6_0
Fixed · RHSA-2010:0865
Red Hat Enterprise Linux 6 Supplementary
java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el6
Fixed · RHSA-2010:0873
Red Hat Enterprise Linux 6 Supplementary
java-1.6.0-ibm-1:1.6.0.9.0-1jpp.4.el6
Fixed · RHSA-2010:0987
Red Hat Network Satellite Server v 5.4
java-1.6.0-ibm-1:1.6.0.9.1-1jpp.1.el5
Fixed · RHSA-2011:0880
Supplementary for Red Hat Enterprise Linux 5
java-1.4.2-ibm-0:1.4.2.13.6-1jpp.2.el5
Fixed · RHSA-2010:0786
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el5
Fixed · RHSA-2010:0807
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-ibm-1:1.6.0.9.0-1jpp.3.el5
Fixed · RHSA-2010:0987
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.22-1jpp.1.el5
Fixed · RHSA-2010:0770
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 3 | java-1.4.2-ibm-0:1.4.2.13.6-1jpp.3.el3 | Fixed | RHSA-2010:0786 |
| Extras for RHEL 4 | java-1.4.2-ibm-0:1.4.2.13.6-1jpp.2.el4 | Fixed | RHSA-2010:0786 |
| Extras for RHEL 4 | java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el4 | Fixed | RHSA-2010:0807 |
| Extras for RHEL 4 | java-1.6.0-ibm-1:1.6.0.9.0-1jpp.3.el4 | Fixed | RHSA-2010:0987 |
| Extras for RHEL 4 | java-1.6.0-sun-1:1.6.0.22-1jpp.1.el4 | Fixed | RHSA-2010:0770 |
| RHEL 4 for SAP | java-1.4.2-ibm-sap-0:1.4.2.13.6.sap-1jpp.1.el4_8 | Fixed | RHSA-2010:0986 |
| RHEL 5 for SAP | java-1.4.2-ibm-sap-0:1.4.2.13.6.sap-1jpp.1.el5 | Fixed | RHSA-2010:0986 |
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk-1:1.6.0.0-1.16.b17.el5 | Fixed | RHSA-2010:0768 |
| Red Hat Enterprise Linux 6 | java-1.6.0-openjdk-1:1.6.0.0-1.31.b17.el6_0 | Fixed | RHSA-2010:0865 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el6 | Fixed | RHSA-2010:0873 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.6.0-ibm-1:1.6.0.9.0-1jpp.4.el6 | Fixed | RHSA-2010:0987 |
| Red Hat Network Satellite Server v 5.4 | java-1.6.0-ibm-1:1.6.0.9.1-1jpp.1.el5 | Fixed | RHSA-2011:0880 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.4.2-ibm-0:1.4.2.13.6-1jpp.2.el5 | Fixed | RHSA-2010:0786 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el5 | Fixed | RHSA-2010:0807 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-ibm-1:1.6.0.9.0-1jpp.3.el5 | Fixed | RHSA-2010:0987 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.22-1jpp.1.el5 | Fixed | RHSA-2010:0770 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (37)
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c02616748 vendor-advisoryx_refsource_HP
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00005.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=134254866602253&w=2 vendor-advisoryx_refsource_HP
- http://secunia.com/advisories/41967 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/41972 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42974 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/44954 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201406-32.xml vendor-advisoryx_refsource_GENTOO
- http://support.avaya.com/css/P8/documents/100114315 x_refsource_CONFIRM
- http://support.avaya.com/css/P8/documents/100114327 x_refsource_CONFIRM
- http://support.avaya.com/css/P8/documents/100123193 x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0768.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0770.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0786.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0807.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0865.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0873.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0986.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0987.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2011-0880.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/516397/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/43979 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-1010-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2010/2745 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-3562 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=639897 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-3562
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11893 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12450 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2010-3562
Change history (0)
No recorded changes yet.