CVE-2012-0547
published 2012-08-30CVE-2012-0547: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact…
PriorityP422low10CVSS 2.0
AVNACLAuNCNINAN
EXPLOIT
EPSS
12.47%
95.8th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | <= 1.6.0 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | <= 1.6.0 | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.00.0NONEAV:N/AC:L/Au:N/C:N/I:N/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2012-09-03·CVSS 10.0
CVE-2012-0547 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Two security issues were fixed in OpenJDK 6.
It was discovered that the Beans component in OpenJDK 6 did not
properly prevent access to restricted classes. A remote attacker could
use this to create an untrusted Java applet or application that would
bypass Java sandbox restrictions. (CVE-2012-1682)
It was discovered that functionality in the AWT component in OpenJDK 6
made it easier for a remote attacker, in conjunction with other
vulnerabilities, to bypass Java sandbox restrictions. (CVE-2012-0547)
Instructions: After a standard system update you need to restart any Java applets
or applications to make all the necessary changes.
Red Hat
OpenJDK: AWT hardening fixes (AWT, 7163201)
vendor_redhat·2012-08-30
CVE-2012-0547 [NONE] OpenJDK: AWT hardening fixes (AWT, 7163201)
OpenJDK: AWT hardening fixes (AWT, 7163201)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.7.0-ibm (R
Red Hat
php: command line arguments injection when run in CGI mode (VU#520827)
vendor_redhat·2012-05-03·CVSS 9.8
CVE-2012-1823 [CRITICAL] php: command line arguments injection when run in CGI mode (VU#520827)
php: command line arguments injection when run in CGI mode (VU#520827)
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.
Statement: This flaw did not affect the versions of PHP in Red Hat Enterprise Linux 3 or 4. Updates were released for Red Hat Enterprise Linux 5 and 6 (RHSA-2012:0546, RHSA-2012:0547), Red Hat Enterprise Linux 5.3 Long Life (RHSA-2012:0568), Red Hat Enterprise Linux 5.6, 6.0, and 6.1 Extended Update Support (RHSA-2012:0568, RHSA-2012:0569), and Red Hat Appli
GHSA
GHSA-mpj2-6qj6-74jr: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has n
ghsa_unreviewed·2022-05-04
CVE-2012-0547 [LOW] GHSA-mpj2-6qj6-74jr: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has n
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."
No detection rules found.
Bugzilla
CVE-2012-0547 OpenJDK: AWT hardening fixes (AWT, 7163201)
bugzilla·2012-08-30
CVE-2012-0547 [NONE] CVE-2012-0547 OpenJDK: AWT hardening fixes (AWT, 7163201)
CVE-2012-0547 OpenJDK: AWT hardening fixes (AWT, 7163201)
Oracle Java SE 7 Update 7 and 6 Update 35 include a "security-in-depth" fix for the AWT component. This fix changes the component to remove functionality that can be used in exploits trying to bypass Java sandbox restrictions, such as the 0day exploit published in August 2012 (see bug 852051), which took advantage of SunToolkit.getField method to modify object's private field.
References:
https://blogs.oracle.com/security/entry/security_alert_for_cve_20121
http://www.oracle.com/technetwork/java/javase/6u35-relnotes-1835788.html
http://www.oracle.com/technetwork/java/javase/7u7-relnotes-1835816.html
External Reference:
http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.html
Discussion:
Mitre descriptio
Krebs
Apple Releases Fix for Critical Java Flaw
blogs_krebs·2012-09-05·CVSS 9.8
[CRITICAL] Apple Releases Fix for Critical Java Flaw
Apple has issued an update for Mac OS X installations of Java that fixes at least one critical security vulnerability in the software.
If you own a Mac, take a moment today to run the Software Update application and check if there is a Java update available. Delaying this action could set your Mac up for a date with malware. In April, the Flashback Trojan infected more than 650,000 Mac systems using an exploit for a critical Java flaw.
Java for Mac OS X 10.6 Update 10 and Java for OS X 2012-005 are available for Java installations on OS X 10.6, OS X Lion and Mountain Lion systems, via Software Update or from Apple Downloads.
Apple stopped bundling Java by default in OS X 10.7 (Lion), but it offers instructions for downloading and installing the software framework when users access webpa
Krebs
Apple Releases Fix for Critical Java Flaw – Krebs on Security
blogs_krebs·2012-09-01·CVSS 9.8
[CRITICAL] Apple Releases Fix for Critical Java Flaw – Krebs on Security
Apple has issued an update for Mac OS X installations of Java that fixes at least one critical security vulnerability in the software.
If you own a Mac, take a moment today to run the Software Update application and check if there is a Java update available. Delaying this action could set your Mac up for a date with malware. In April, the Flashback Trojan infected more than 650,000 Mac systems using an exploit for a critical Java flaw.
Java for Mac OS X 10.6 Update 10 and Java for OS X 2012-005 are available for Java installations on OS X 10.6, OS X Lion and Mountain Lion systems, via Software Update or from Apple Downloads .
Apple stopped bundling Java by default in OS X 10.7 (Lion), but it offers instructions for downloading and installing the software framework when users access webp
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.htmlhttp://marc.info/?l=bugtraq&m=135161897205627&w=2http://rhn.redhat.com/errata/RHSA-2012-1222.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1225.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1392.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1466.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://secunia.com/advisories/51044http://secunia.com/advisories/51141http://secunia.com/advisories/51327http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS12-023/index.htmlhttp://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.htmlhttp://www.securityfocus.com/bid/55339http://www.ubuntu.com/usn/USN-1553-1https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03533078http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.htmlhttp://marc.info/?l=bugtraq&m=135161897205627&w=2http://rhn.redhat.com/errata/RHSA-2012-1222.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1225.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1392.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1466.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://secunia.com/advisories/51044http://secunia.com/advisories/51141http://secunia.com/advisories/51327http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS12-023/index.htmlhttp://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.htmlhttp://www.securityfocus.com/bid/55339http://www.ubuntu.com/usn/USN-1553-1https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03533078
2012-08-30
Published