Sun Java Runtime Environment Information Disclosure Vulnerabilities
BID:21674
Info
Sun Java Runtime Environment Information Disclosure Vulnerabilities
| Bugtraq ID: | 21674 |
| Class: | Design Error |
| CVE: |
CVE-2006-6736 CVE-2006-6737 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2006 12:00AM |
| Updated: | Mar 19 2015 09:13AM |
| Credit: | Tom Hawtin reported these issues to the vendor. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SP1 Sun SDK (Linux Production Release) 1.5 _06 Sun SDK (Linux Production Release) 1.5 _05 Sun SDK (Linux Production Release) 1.5 _04 Sun SDK (Linux Production Release) 1.5 _03 Sun SDK (Linux Production Release) 1.5 _02 Sun SDK (Linux Production Release) 1.5 _01 Sun SDK (Linux Production Release) 1.5 Sun SDK (Linux Production Release) 1.4.2 _10 Sun SDK (Linux Production Release) 1.4.2 _09 Sun SDK (Linux Production Release) 1.4.2 _08 Sun SDK (Linux Production Release) 1.4.2 _07 Sun SDK (Linux Production Release) 1.4.2 _06 Sun SDK (Linux Production Release) 1.4.2 _05 Sun SDK (Linux Production Release) 1.4.2 _04 Sun SDK (Linux Production Release) 1.4.2 _03 Sun SDK (Linux Production Release) 1.4.2 _02 Sun SDK (Linux Production Release) 1.4.2 _01 Sun SDK (Linux Production Release) 1.4.2 Sun SDK (Linux Production Release) 1.4.1 Sun SDK (Linux Production Release) 1.4 Sun SDK (Linux Production Release) 1.3 Sun SDK (Linux Production Release) 1.4.2_11 Sun JRE (Solaris Production Release) 1.3.1 Sun JRE (Solaris Production Release) 1.3 _04 Sun JRE (Solaris Production Release) 1.3 _03 Sun JRE (Solaris Production Release) 1.3 _01 Sun JRE (Linux Production Release) 1.5 _05 Sun JRE (Linux Production Release) 1.5 _04 Sun JRE (Linux Production Release) 1.5 _03 Sun JRE (Linux Production Release) 1.5 _02 Sun JRE (Linux Production Release) 1.5 _01 Sun JRE (Linux Production Release) 1.4.2 _10-b03 Sun JRE (Linux Production Release) 1.4.2 _09 Sun JRE (Linux Production Release) 1.4.2 _08 Sun JRE (Linux Production Release) 1.4.2 _07 Sun JRE (Linux Production Release) 1.4.2 _06 Sun JRE (Linux Production Release) 1.4.2 _05 Sun JRE (Linux Production Release) 1.4.2 _04 Sun JRE (Linux Production Release) 1.4.2 _03 Sun JRE (Linux Production Release) 1.4.2 _02 Sun JRE (Linux Production Release) 1.4.2 _01 Sun JRE (Linux Production Release) 1.4.2 Sun JRE (Linux Production Release) 1.4.1 Sun JRE (Linux Production Release) 1.3.1 _18 Sun JRE (Linux Production Release) 1.3.1 _17 Sun JRE (Linux Production Release) 1.3.1 _16 Sun JRE (Linux Production Release) 1.3.1 _15 Sun JRE (Linux Production Release) 1.3.1 _08 Sun JRE (Linux Production Release) 1.3.1 _04 Sun JRE (Linux Production Release) 1.3.1 _01a Sun JRE (Linux Production Release) 1.3.1 _01 Sun JRE (Linux Production Release) 1.3 .0_05 Sun JRE (Linux Production Release) 1.3 .0_02 Sun JRE (Linux Production Release) 1.3 .0 Sun JRE (Linux Production Release) 1.4.2_12 Sun JRE (Linux Production Release) 1.4.2_11 Sun Java 2 Standard Edition SDK 1.3.1 .x S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 0 RedHat Enterprise Linux WS 2.1 IA64 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux Extras 4 RedHat Enterprise Linux Extras 3 RedHat Enterprise Linux ES 2.1 IA64 RedHat Enterprise Linux ES 2.1 Red Hat Enterprise Linux AS 2.1 IA64 Red Hat Enterprise Linux AS 2.1 Gentoo Linux Avaya Interactive Response 1.3 Avaya Interactive Response 2.0 Avaya Integrated Management Avaya CVLAN Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 |
| Not Vulnerable: |
Sun SDK (Linux Production Release) 1.5 _07 Sun SDK (Linux Production Release) 1.3.1 _19 Sun SDK (Linux Production Release) 1.4.2_13 Sun JRE (Linux Production Release) 1.5 _07 Sun JRE (Linux Production Release) 1.3.1 _19 Sun JRE (Linux Production Release) 1.4.2_13 |
Discussion
Sun Java Runtime Environment Information Disclosure Vulnerabilities
The Sun Java Runtime Environment is prone to multiple information-disclosure vulnerabilities because of a design flaw in the affected application.
An attacker can exploit these issues to access sensitive information. This may lead to other attacks.
The Sun Java Runtime Environment is prone to multiple information-disclosure vulnerabilities because of a design flaw in the affected application.
An attacker can exploit these issues to access sensitive information. This may lead to other attacks.
Exploit / POC
Sun Java Runtime Environment Information Disclosure Vulnerabilities
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Sun Java Runtime Environment Information Disclosure Vulnerabilities
Solution:
The vendor has released an advisory along with updates to address these issues. Please see the references for more information.
Apple Mac OS X 10.4.10
Apple Mac OS X Server 10.4.10
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Solution:
The vendor has released an advisory along with updates to address these issues. Please see the references for more information.
Apple Mac OS X 10.4.10
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
Apple Mac OS X Server 10.4.10
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
Apple Mac OS X 10.4.11
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
Apple Mac OS X Server 10.4.11
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
References
Sun Java Runtime Environment Information Disclosure Vulnerabilities
References:
References:
- Novell: Security update for IBM Java (Novell)
- Novell: Security update for Java (Novell)
- Sun Alert ID: 102732 (Sun)
- Sun Homepage (Sun Microsystems )
- About the security content of Java Release 6 for Mac OS X 10.4 (Apple)
- ASA-2007-023 - Security Vulnerabilities in the Java Runtime Environment may Allo (Avaya)
- ASA-2007-091 - Security Vulnerabilities in Java (Avaya)
- RHSA-2007:0062-2: java-1.4.2-ibm security update (Red Hat)
- RHSA-2007:0072-2: IBMJava2 security update (Red Hat)