CVE-2012-0503
Publication date 15 February 2012
Last updated 24 July 2024
Ubuntu priority
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to I18n.
Status
Package | Ubuntu Release | Status |
---|---|---|
icedtea-web | ||
openjdk-6 | ||
openjdk-6b18 | ||
openjdk-7 | ||
sun-java5 | ||
sun-java6 | ||
Notes
mdeslaur
in natty+, NetX and the plugin moved to the icedtea-web package
sbeattie
red hat description: It was discovered that the use of TimeZone.setDefault() was not restricted by the SecurityManager, allowing an untrusted Java application or applet to set a new default time zone, and hence bypass Java sandbox restrictions.
References
Related Ubuntu Security Notices (USN)
- USN-1373-1
- OpenJDK 6 vulnerabilities
- 24 February 2012
- USN-1373-2
- OpenJDK 6 (ARM) vulnerabilities
- 1 March 2012