CVE-2010-0839
published 2010-04-01CVE-2010-0839: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.54%
87.9th percentile
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Affected
163 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.6.0 | — |
| sun | jdk | <= 1.5.0 | — |
| sun | jdk | <= 1.3.1_27 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
vendor_vmware·2011-02-10·CVSS 5.0
CVE-2008-0085 [MEDIUM] Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
VMSA-2011-0003: Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX VMware Security Advisory VMware Security Advisory Advisory ID: VMware Security Advisory Synopsis: Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX VMware Security Advisory Issue date: VMware Security Advisory Updated on: VMware Security Advisory CVE numbers:
CVEs: CVE-2008-0085, CVE-2008-0086, CVE-2008-0106, CVE-2008-0107, CVE-2008-3825, CVE-2008-5416, CVE-2009-1384, CVE-2009-2693, CVE-2009-2901, CVE-2009-2902, CVE-2009-3548, CVE-2009-3555, CVE-2009-4308, CVE-2010-0003, CVE-2010-0007, CVE-2010-0008, CVE-2010-0082, CVE-2010-0084, CVE-2010-0085,
Red Hat
kernel panic via futex
vendor_redhat·2010-11-09·CVSS 4.9
CVE-2010-3086 [MEDIUM] kernel panic via futex
kernel panic via futex
include/asm-x86/futex.h in the Linux kernel before 2.6.25 does not properly implement exception fixup, which allows local users to cause a denial of service (panic) via an invalid application that triggers a page fault.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat
Enterprise Linux 3 and 4 as they did not support for the FUTEX_LOCK_PI futex operation. It did not affect the version of Linux kernel as shipped with Red Hat Enterprise MRG as it has already had the fix to this issue. This issue was addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2010-0839.html
Red Hat
kernel: xfs: XFS_IOC_FSGETXATTR ioctl memory leak
vendor_redhat·2010-09-07·CVSS 5.5
CVE-2010-3078 [MEDIUM] CWE-401 kernel: xfs: XFS_IOC_FSGETXATTR ioctl memory leak
kernel: xfs: XFS_IOC_FSGETXATTR ioctl memory leak
The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an ioctl call.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat
Enterprise Linux 3, 4, and Red Hat Enterprise MRG as they did not include
support for the XFS file system. This issue was addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2010-0839.html
Red Hat
JDK multiple unspecified vulnerabilities
vendor_redhat·2010-03-30·CVSS 7.5
CVE-2010-0839 [HIGH] JDK multiple unspecified vulnerabilities
JDK multiple unspecified vulnerabilities
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Red Hat
kernel: io_submit_one() NULL ptr deref
vendor_redhat·2007-08-08·CVSS 4.9
CVE-2010-3066 [MEDIUM] kernel: io_submit_one() NULL ptr deref
kernel: io_submit_one() NULL ptr deref
The io_submit_one function in fs/aio.c in the Linux kernel before 2.6.23 allows local users to cause a denial of service (NULL pointer dereference) via a crafted io_submit system call with an IOCB_FLAG_RESFD flag.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat
Enterprise Linux 3 and 4 as they did not include support for eventfd in the
Async I/O (AIO) implementation. It did not affect the version of Linux kernel
as shipped with Red Hat Enterprise MRG as it has already had the fix to this
issue. This issue was addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2010-0839.html
GHSA
GHSA-xjcv-f3gw-h9m2: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5
ghsa_unreviewed·2022-05-02
CVE-2010-0839 [HIGH] GHSA-xjcv-f3gw-h9m2: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3477 kernel: net/sched/act_police.c infoleak
bugzilla·2010-09-22·CVSS 5.5
CVE-2010-3477 [MEDIUM] CVE-2010-3477 kernel: net/sched/act_police.c infoleak
CVE-2010-3477 kernel: net/sched/act_police.c infoleak
Description of problem:
While reviewing commit 1c40be12f7d8ca1d387510d39787b12e512a7ce8 (CVE-2010-2942), Jeff Mahoney audited other users of tc_action_ops->dump for information leaks.
That commit covered almost all of them but act_police still had a leak.
opt.limit and opt.capab aren't zeroed out before the structure is passed out.
Upstream commit:
http://git.kernel.org/linus/0f04cfd098fb81fded74e78ea1a1b86cc6c6c31e
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Via RHSA-2010:0779 https://rhn.redhat.com/errata/RHSA-2010-0779.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0839 https://rhn.redhat.com/errata/RHSA-2010-0839.html
Bugzilla
CVE-2010-3078 kernel: xfs: XFS_IOC_FSGETXATTR ioctl memory leak
bugzilla·2010-09-07·CVSS 5.5
CVE-2010-3078 [MEDIUM] CVE-2010-3078 kernel: xfs: XFS_IOC_FSGETXATTR ioctl memory leak
CVE-2010-3078 kernel: xfs: XFS_IOC_FSGETXATTR ioctl memory leak
Description of problem:
The XFS_IOC_FSGETXATTR ioctl allows unprivileged users to read 12 bytes of uninitialized stack memory, because the fsxattr struct declared on the stack in xfs_ioc_fsgetxattr() does not alter (or zero) the 12-byte fsx_pad member before copying it back to the user.
http://www.linux.sgi.com/archives/xfs-masters/2010-09/msg00002.html
Acknowledgements:
Red Hat would like to thank Dan Rosenberg for reporting this issue.
Discussion:
Patch:
http://groups.google.com/group/linux.kernel/browse_thread/thread/d91e3a963e760a62/6e2a940395ed2911?show_docid=6e2a940395ed2911
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0839 https://rhn.redhat.com/errata/RHSA-
Bugzilla
CVE-2010-3448 kernel: thinkpad-acpi: lock down video output state access [rhel-5.5.z]
bugzilla·2010-09-01·CVSS 4.9
CVE-2010-3448 [MEDIUM] CVE-2010-3448 kernel: thinkpad-acpi: lock down video output state access [rhel-5.5.z]
CVE-2010-3448 kernel: thinkpad-acpi: lock down video output state access [rhel-5.5.z]
This bug has been copied from bug #607037 and has been proposed
to be backported to 5.5 z-stream (EUS).
Discussion:
in kernel 2.6.18-194.19.1.el5
linux-2.6-acpi-thinkpad-acpi-lock-down-video-output-state-access.patch
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2010-0839.html
---
Technical note added. If any revisions are required, please edit the "Technical Notes" field
Bugzilla
CVE-2010-0839 CVE-2010-0842 CVE-2010-0843 CVE-2010-0844 JDK multiple unspecified vulnerabilities
bugzilla·2010-03-31·CVSS 7.5
CVE-2010-0839 [HIGH] CVE-2010-0839 CVE-2010-0842 CVE-2010-0843 CVE-2010-0844 JDK multiple unspecified vulnerabilities
CVE-2010-0839 CVE-2010-0842 CVE-2010-0843 CVE-2010-0844 JDK multiple unspecified vulnerabilities
Update 19 of Oracle/Sun Java fixes multiple unspecified vulnerabilities. (CVE-2010-0839, CVE-2010-0842, CVE-2010-0843, CVE-2010-0844)
Reference:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0337 https://rhn.redhat.com/errata/RHSA-2010-0337.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Supplementary for RHEL 5.2.z
Supplementary for RHEL 5.3.z
Via RHSA-2010:0338 https://rhn.redhat.com/errata/RHSA-2010-0338.html
---
This issue has been
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://marc.info/?l=bugtraq&m=127557596201693&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/39317http://secunia.com/advisories/39659http://secunia.com/advisories/40545http://secunia.com/advisories/43308http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlhttp://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0337.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0338.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0383.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0471.htmlhttp://www.securityfocus.com/archive/1/516397/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0003.htmlhttp://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.htmlhttp://www.vupen.com/english/advisories/2010/1454http://www.vupen.com/english/advisories/2010/1793https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13357http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://marc.info/?l=bugtraq&m=127557596201693&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/39317http://secunia.com/advisories/39659http://secunia.com/advisories/40545http://secunia.com/advisories/43308http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlhttp://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0337.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0338.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0383.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0471.htmlhttp://www.securityfocus.com/archive/1/516397/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0003.htmlhttp://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.htmlhttp://www.vupen.com/english/advisories/2010/1454http://www.vupen.com/english/advisories/2010/1793https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13357
2010-04-01
Published