CVE-2012-0506
published 2012-02-15CVE-2012-0506: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.13%
79.8th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to CORBA.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jre | <= 1.6.0 | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| sun | jre | <= 1.4.2_35 | — |
| sun | jre | <= 1.5.0 | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu6.4MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 6 (ARM) vulnerabilities
vendor_ubuntu·2012-03-01·CVSS 6.4
CVE-2012-0501 [MEDIUM] OpenJDK 6 (ARM) vulnerabilities
Title: OpenJDK 6 (ARM) vulnerabilities
Summary: Multiple vulnerabilities in OpenJDK 6 for the ARM architecture have
been fixed.
USN 1373-1 fixed vulnerabilities in OpenJDK 6 in Ubuntu 10.04 LTS,
Ubuntu 10.10 and Ubuntu 11.04 for all architectures except for ARM
(armel). This provides the corresponding OpenJDK 6 update for use
with the ARM (armel) architecture in Ubuntu 10.04 LTS, Ubuntu 10.10
and Ubuntu 11.04.
Original advisory details:
It was discovered that the Java HttpServer class did not limit the
number of headers read from a HTTP request. A remote attacker could
cause a denial of service by sending special requests that trigger
hash collisions predictably. (CVE-2011-5035)
ATTENTION: this update changes previous Java HttpServer class behavior
by limiting the number of request he
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2012-02-24·CVSS 6.4
CVE-2011-3563 [MEDIUM] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Multiple OpenJDK 6 vulnerabilities have been fixed.
It was discovered that the Java HttpServer class did not limit the
number of headers read from a HTTP request. A remote attacker could
cause a denial of service by sending special requests that trigger
hash collisions predictably. (CVE-2011-5035)
ATTENTION: this update changes previous Java HttpServer class behavior
by limiting the number of request headers to 200. This may be increased
by adjusting the sun.net.httpserver.maxReqHeaders property.
It was discovered that the Java Sound component did not properly
check buffer boundaries. A remote attacker could use this to cause
a denial of service or view confidential data. (CVE-2011-3563)
It was discovered that the Java2D implementation does no
Red Hat
OpenJDK: mutable repository identifiers (CORBA, 7110704)
vendor_redhat·2012-02-14·CVSS 4.3
CVE-2012-0506 [MEDIUM] OpenJDK: mutable repository identifiers (CORBA, 7110704)
OpenJDK: mutable repository identifiers (CORBA, 7110704)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to CORBA.
Package: java-1.6.0-sun (Red Hat Enterprise Linux 4) - Affected
GHSA
GHSA-9c5v-r999-w34j: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5
ghsa_unreviewed·2022-05-04
CVE-2012-0506 [MEDIUM] GHSA-9c5v-r999-w34j: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to CORBA.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1719 OpenJDK: mutable repository identifiers in generated stub code (CORBA, 7143851)
bugzilla·2012-06-06·CVSS 4.3
CVE-2012-1719 [MEDIUM] CVE-2012-1719 OpenJDK: mutable repository identifiers in generated stub code (CORBA, 7143851)
CVE-2012-1719 OpenJDK: mutable repository identifiers in generated stub code (CORBA, 7143851)
CVE-2012-0506 (bug #789300) was assigned to the flaw in the Java CORBA implementation that allowed modification of the repository identifiers that are intended to be immutable. This additional fix corrects the problem in the stub generator for generated stub code.
Discussion:
Public now via:
http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html
Fixed in Oracle Java 7 Update 5 and 6 Update 33.
---
The fix for this issue is or will be included in the following IcedTea versions:
* IcedTea6 1.10.8
* IcedTea6 1.11.3
* IcedTea7 2.1.1
* IcedTea7 2.2.1
IcedTea6 releases announcement:
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.html
http://blog.fu
Bugzilla
CVE-2012-0506 OpenJDK: mutable repository identifiers (CORBA, 7110704)
bugzilla·2012-02-10·CVSS 4.3
CVE-2012-0506 [MEDIUM] CVE-2012-0506 OpenJDK: mutable repository identifiers (CORBA, 7110704)
CVE-2012-0506 OpenJDK: mutable repository identifiers (CORBA, 7110704)
It was discovered that Corba implementation in Java did not properly protect repository identifiers (that can be obtained using _ids() method) on certain Corba objects. This could have been used to perform modification of the data that should have been immutable.
Discussion:
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2012:0135 https://rhn.redhat.com/errata/RHSA-2012-0135.html
---
Patches were applied in following IcedTea versions:
* IcedTea6 1.8.13 (based on OpenJDK6 b18)
* IcedTea6 1.9.13 (based on OpenJDK6 b20)
* IcedTea6 1.10.6 (based on OpenJDK6 b22)
* IcedTea6
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-06/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-07/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00015.htmlhttp://marc.info/?l=bugtraq&m=133364885411663&w=2http://marc.info/?l=bugtraq&m=133365109612558&w=2http://marc.info/?l=bugtraq&m=133728004526190&w=2http://marc.info/?l=bugtraq&m=133847939902305&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://marc.info/?l=bugtraq&m=134254957702612&w=2http://rhn.redhat.com/errata/RHSA-2012-0508.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0514.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0702.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1080.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://secunia.com/advisories/48073http://secunia.com/advisories/48074http://secunia.com/advisories/48589http://secunia.com/advisories/48692http://secunia.com/advisories/48915http://secunia.com/advisories/48948http://secunia.com/advisories/48950http://secunia.com/advisories/49198http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.debian.org/security/2012/dsa-2420http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.htmlhttp://www.securityfocus.com/bid/52014https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14082http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-06/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-07/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00015.htmlhttp://marc.info/?l=bugtraq&m=133364885411663&w=2http://marc.info/?l=bugtraq&m=133365109612558&w=2http://marc.info/?l=bugtraq&m=133728004526190&w=2http://marc.info/?l=bugtraq&m=133847939902305&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://marc.info/?l=bugtraq&m=134254957702612&w=2http://rhn.redhat.com/errata/RHSA-2012-0508.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0514.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0702.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1080.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://secunia.com/advisories/48073http://secunia.com/advisories/48074http://secunia.com/advisories/48589http://secunia.com/advisories/48692http://secunia.com/advisories/48915http://secunia.com/advisories/48948http://secunia.com/advisories/48950http://secunia.com/advisories/49198http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.debian.org/security/2012/dsa-2420http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.htmlhttp://www.securityfocus.com/bid/52014https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14082
2012-02-15
Published