OpenJDK JAXP untrusted component state manipulation (6927050)
Published Feb 17, 2011
5.0
MEDIUMCVSS 2.0
EPSS 3.48%
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23, and, and earlier allows remote attackers to affect availability via unknown vectors related to JAXP and unspecified APIs. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is related to "Features set on SchemaFactory not inherited by Validator."
Affected products
No data.
Configuration 1
- ≤ 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
Configuration 2
- ≤ 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
No data.
Extras for RHEL 4
java-1.6.0-sun-1:1.6.0.24-1jpp.1.el4
Fixed · RHSA-2011:0282
Red Hat Enterprise Linux 5
java-1.6.0-openjdk-1:1.6.0.0-1.20.b17.el5
Fixed · RHSA-2011:0281
Red Hat Enterprise Linux 6
java-1.6.0-openjdk-1:1.6.0.0-1.39.b17.el6_0
Fixed · RHSA-2011:0281
Red Hat Enterprise Linux 6 Supplementary
java-1.6.0-sun-1:1.6.0.24-1jpp.1.el6
Fixed · RHSA-2011:0282
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.24-1jpp.1.el5
Fixed · RHSA-2011:0282
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 4 | java-1.6.0-sun-1:1.6.0.24-1jpp.1.el4 | Fixed | RHSA-2011:0282 |
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk-1:1.6.0.0-1.20.b17.el5 | Fixed | RHSA-2011:0281 |
| Red Hat Enterprise Linux 6 | java-1.6.0-openjdk-1:1.6.0.0-1.39.b17.el6_0 | Fixed | RHSA-2011:0281 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.6.0-sun-1:1.6.0.24-1jpp.1.el6 | Fixed | RHSA-2011:0282 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.24-1jpp.1.el5 | Fixed | RHSA-2011:0282 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (21)
- http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054115.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054134.html vendor-advisoryx_refsource_FEDORA
- http://marc.info/?l=bugtraq&m=134254866602253&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=134254957702612&w=2 vendor-advisoryx_refsource_HP
- http://secunia.com/advisories/43350 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://security.gentoo.org/glsa/glsa-201406-32.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2011/dsa-2224 vendor-advisoryx_refsource_DEBIAN
- http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS11-003/index.html x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:054 vendor-advisoryx_refsource_MANDRIVA
- http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.oracle.com/technetwork/topics/security/javacpufeb2011-304611.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0281.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0282.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.securityfocus.com/bid/46387 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2010-4470 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=676005 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65404 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2010-4470
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12887 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14076 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2010-4470
Change history (0)
No recorded changes yet.