Oracle Java SE and Java for Business JRE Trusted Method Chaining Remote Code Execution Vulnerability
BID:39065
Info
Oracle Java SE and Java for Business JRE Trusted Method Chaining Remote Code Execution Vulnerability
| Bugtraq ID: | 39065 |
| Class: | Design Error |
| CVE: |
CVE-2010-0840 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 30 2010 12:00AM |
| Updated: | Apr 13 2015 09:53PM |
| Credit: | Sami Koivu |
| Vulnerable: |
Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 9.04 sparc Ubuntu Ubuntu Linux 9.04 powerpc Ubuntu Ubuntu Linux 9.04 lpia Ubuntu Ubuntu Linux 9.04 i386 Ubuntu Ubuntu Linux 9.04 amd64 Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise Server 11 SuSE SUSE Linux Enterprise Server 10 SP3 SuSE SUSE Linux Enterprise SDK 11 SP1 SuSE SUSE Linux Enterprise SDK 11 SuSE Suse Linux Enterprise Desktop 10 SP3 SuSE SUSE Linux Enterprise 11 SP1 SuSE SUSE Linux Enterprise 11 SuSE SUSE Linux Enterprise 10 SP3 Sun JRE (Windows Production Release) 1.6 _17 Sun JRE (Windows Production Release) 1.6 _13 Sun JRE (Windows Production Release) 1.6 _12 Sun JRE (Windows Production Release) 1.6 _10 Sun JRE (Windows Production Release) 1.6 _07 Sun JRE (Windows Production Release) 1.6 _06 Sun JRE (Windows Production Release) 1.6 _05 Sun JRE (Windows Production Release) 1.6 _04 Sun JRE (Windows Production Release) 1.6 Sun JRE (Windows Production Release) 1.5 _22 Sun JRE (Windows Production Release) 1.5 _18 Sun JRE (Windows Production Release) 1.5 _16 Sun JRE (Windows Production Release) 1.5 _15 Sun JRE (Windows Production Release) 1.5 _06 Sun JRE (Windows Production Release) 1.5 _05 Sun JRE (Windows Production Release) 1.5 _04 Sun JRE (Windows Production Release) 1.5 _03 Sun JRE (Windows Production Release) 1.5 _02 Sun JRE (Windows Production Release) 1.5 _01 Sun JRE (Windows Production Release) 1.5 Sun JRE (Windows Production Release) 1.4.2 _24 Sun JRE (Windows Production Release) 1.4.2 _10 Sun JRE (Windows Production Release) 1.4.2 _09 Sun JRE (Windows Production Release) 1.4.2 _09 Sun JRE (Windows Production Release) 1.4.2 _08 Sun JRE (Windows Production Release) 1.4.2 _08 Sun JRE (Windows Production Release) 1.4.2 _07 Sun JRE (Windows Production Release) 1.4.2 _07 Sun JRE (Windows Production Release) 1.4.2 _06 Sun JRE (Windows Production Release) 1.4.2 _05 Sun JRE (Windows Production Release) 1.4.2 _04 Sun JRE (Windows Production Release) 1.4.2 _03 Sun JRE (Windows Production Release) 1.4.2 _02 Sun JRE (Windows Production Release) 1.4.2 _01 Sun JRE (Windows Production Release) 1.4.2 Sun JRE (Windows Production Release) 1.6.0_18 Sun JRE (Windows Production Release) 1.6.0_15 Sun JRE (Windows Production Release) 1.6.0_14 Sun JRE (Windows Production Release) 1.6.0_11 Sun JRE (Windows Production Release) 1.6.0_03 Sun JRE (Windows Production Release) 1.6.0_02 Sun JRE (Windows Production Release) 1.6.0_01 Sun JRE (Windows Production Release) 1.5.0_23 Sun JRE (Windows Production Release) 1.5.0_20 Sun JRE (Windows Production Release) 1.5.0_17 Sun JRE (Windows Production Release) 1.5.0_14 Sun JRE (Windows Production Release) 1.5.0_13 Sun JRE (Windows Production Release) 1.5.0_12 Sun JRE (Windows Production Release) 1.5.0_11 Sun JRE (Windows Production Release) 1.5.0_10 Sun JRE (Windows Production Release) 1.5.0.0_09 Sun JRE (Windows Production Release) 1.5.0.0_08 Sun JRE (Windows Production Release) 1.5.0.0_07 Sun JRE (Windows Production Release) 1.4.2_25 Sun JRE (Windows Production Release) 1.4.2_22 Sun JRE (Windows Production Release) 1.4.2_20 Sun JRE (Windows Production Release) 1.4.2_19 Sun JRE (Windows Production Release) 1.4.2_18 Sun JRE (Windows Production Release) 1.4.2_17 Sun JRE (Windows Production Release) 1.4.2_16 Sun JRE (Windows Production Release) 1.4.2_15 Sun JRE (Windows Production Release) 1.4.2_14 Sun JRE (Windows Production Release) 1.4.2_13 Sun JRE (Windows Production Release) 1.4.2_12 Sun JRE (Windows Production Release) 1.4.2_11 Sun JRE (Solaris Production Release) 1.6 _17 Sun JRE (Solaris Production Release) 1.6 _13 Sun JRE (Solaris Production Release) 1.6 _12 Sun JRE (Solaris Production Release) 1.6 _10 Sun JRE (Solaris Production Release) 1.6 _07 Sun JRE (Solaris Production Release) 1.6 _06 Sun JRE (Solaris Production Release) 1.6 _05 Sun JRE (Solaris Production Release) 1.6 _04 Sun JRE (Solaris Production Release) 1.6 Sun JRE (Solaris Production Release) 1.5 _22 Sun JRE (Solaris Production Release) 1.5 _18 Sun JRE (Solaris Production Release) 1.5 _16 Sun JRE (Solaris Production Release) 1.5 _15 Sun JRE (Solaris Production Release) 1.5 _06 Sun JRE (Solaris Production Release) 1.5 _05 Sun JRE (Solaris Production Release) 1.5 _04 Sun JRE (Solaris Production Release) 1.5 _03 Sun JRE (Solaris Production Release) 1.5 _02 Sun JRE (Solaris Production Release) 1.5 _01 Sun JRE (Solaris Production Release) 1.5 Sun JRE (Solaris Production Release) 1.4.2 _24 Sun JRE (Solaris Production Release) 1.4.2 _10 Sun JRE (Solaris Production Release) 1.4.2 _09 Sun JRE (Solaris Production Release) 1.4.2 _09 Sun JRE (Solaris Production Release) 1.4.2 _08 Sun JRE (Solaris Production Release) 1.4.2 _08 Sun JRE (Solaris Production Release) 1.4.2 _07 Sun JRE (Solaris Production Release) 1.4.2 _07 Sun JRE (Solaris Production Release) 1.4.2 _06 Sun JRE (Solaris Production Release) 1.4.2 _05 Sun JRE (Solaris Production Release) 1.4.2 _04 Sun JRE (Solaris Production Release) 1.4.2 _03 Sun JRE (Solaris Production Release) 1.4.2 _02 Sun JRE (Solaris Production Release) 1.4.2 _01 Sun JRE (Solaris Production Release) 1.4.2 Sun JRE (Solaris Production Release) 1.6.0_18 Sun JRE (Solaris Production Release) 1.6.0_15 Sun JRE (Solaris Production Release) 1.6.0_14 Sun JRE (Solaris Production Release) 1.6.0_11 Sun JRE (Solaris Production Release) 1.6.0_03 Sun JRE (Solaris Production Release) 1.6.0_02 Sun JRE (Solaris Production Release) 1.6.0_01 Sun JRE (Solaris Production Release) 1.5.0_23 Sun JRE (Solaris Production Release) 1.5.0_20 Sun JRE (Solaris Production Release) 1.5.0_17 Sun JRE (Solaris Production Release) 1.5.0_14 Sun JRE (Solaris Production Release) 1.5.0_13 Sun JRE (Solaris Production Release) 1.5.0_12 Sun JRE (Solaris Production Release) 1.5.0_11 Sun JRE (Solaris Production Release) 1.5.0_10 Sun JRE (Solaris Production Release) 1.5.0.0_09 Sun JRE (Solaris Production Release) 1.5.0.0_08 Sun JRE (Solaris Production Release) 1.5.0.0_07 Sun JRE (Solaris Production Release) 1.4.2_25 Sun JRE (Solaris Production Release) 1.4.2_22 Sun JRE (Solaris Production Release) 1.4.2_20 Sun JRE (Solaris Production Release) 1.4.2_19 Sun JRE (Solaris Production Release) 1.4.2_18 Sun JRE (Solaris Production Release) 1.4.2_17 Sun JRE (Solaris Production Release) 1.4.2_16 Sun JRE (Solaris Production Release) 1.4.2_15 Sun JRE (Solaris Production Release) 1.4.2_14 Sun JRE (Solaris Production Release) 1.4.2_13 Sun JRE (Solaris Production Release) 1.4.2_12 Sun JRE (Solaris Production Release) 1.4.2_11 Sun JRE (Linux Production Release) 1.6 _17 Sun JRE (Linux Production Release) 1.6 _13 Sun JRE (Linux Production Release) 1.6 _12 Sun JRE (Linux Production Release) 1.6 _10 Sun JRE (Linux Production Release) 1.6 _07 Sun JRE (Linux Production Release) 1.6 _06 Sun JRE (Linux Production Release) 1.6 _05 Sun JRE (Linux Production Release) 1.6 _04 Sun JRE (Linux Production Release) 1.6 Sun JRE (Linux Production Release) 1.5 _22 Sun JRE (Linux Production Release) 1.5 _18 Sun JRE (Linux Production Release) 1.5 _16 Sun JRE (Linux Production Release) 1.5 _15 Sun JRE (Linux Production Release) 1.5 _07 Sun JRE (Linux Production Release) 1.5 _06 Sun JRE (Linux Production Release) 1.5 _05 Sun JRE (Linux Production Release) 1.5 _04 Sun JRE (Linux Production Release) 1.5 _03 Sun JRE (Linux Production Release) 1.5 _02 Sun JRE (Linux Production Release) 1.5 _01 Sun JRE (Linux Production Release) 1.5 .0 beta Sun JRE (Linux Production Release) 1.5 Sun JRE (Linux Production Release) 1.4.2 _24 Sun JRE (Linux Production Release) 1.4.2 _10-b03 Sun JRE (Linux Production Release) 1.4.2 _10 Sun JRE (Linux Production Release) 1.4.2 _09 Sun JRE (Linux Production Release) 1.4.2 _08 Sun JRE (Linux Production Release) 1.4.2 _07 Sun JRE (Linux Production Release) 1.4.2 _06 Sun JRE (Linux Production Release) 1.4.2 _05 Sun JRE (Linux Production Release) 1.4.2 _04 Sun JRE (Linux Production Release) 1.4.2 _03 Sun JRE (Linux Production Release) 1.4.2 _02 Sun JRE (Linux Production Release) 1.4.2 _01 Sun JRE (Linux Production Release) 1.4.2 Sun JRE (Linux Production Release) 1.6.0_18 Sun JRE (Linux Production Release) 1.6.0_15 Sun JRE (Linux Production Release) 1.6.0_14 Sun JRE (Linux Production Release) 1.6.0_11 Sun JRE (Linux Production Release) 1.6.0_03 Sun JRE (Linux Production Release) 1.6.0_02 Sun JRE (Linux Production Release) 1.6.0_01 Sun JRE (Linux Production Release) 1.5.0_23 Sun JRE (Linux Production Release) 1.5.0_20 Sun JRE (Linux Production Release) 1.5.0_17 Sun JRE (Linux Production Release) 1.5.0_14 Sun JRE (Linux Production Release) 1.5.0_13 Sun JRE (Linux Production Release) 1.5.0_12 Sun JRE (Linux Production Release) 1.5.0_11 Sun JRE (Linux Production Release) 1.5.0_10 Sun JRE (Linux Production Release) 1.5.0_09 Sun JRE (Linux Production Release) 1.5.0_08 Sun JRE (Linux Production Release) 1.4.2_25 Sun JRE (Linux Production Release) 1.4.2_22 Sun JRE (Linux Production Release) 1.4.2_20 Sun JRE (Linux Production Release) 1.4.2_19 Sun JRE (Linux Production Release) 1.4.2_18 Sun JRE (Linux Production Release) 1.4.2_17 Sun JRE (Linux Production Release) 1.4.2_16 Sun JRE (Linux Production Release) 1.4.2_15 Sun JRE (Linux Production Release) 1.4.2_14 Sun JRE (Linux Production Release) 1.4.2_13 Sun JRE (Linux Production Release) 1.4.2_12 Sun JRE (Linux Production Release) 1.4.2_11 Sun JDK (Windows Production Release) 1.6 _17 Sun JDK (Windows Production Release) 1.6 _14 Sun JDK (Windows Production Release) 1.6 _13 Sun JDK (Windows Production Release) 1.6 _11 Sun JDK (Windows Production Release) 1.6 _10 Sun JDK (Windows Production Release) 1.6 _07 Sun JDK (Windows Production Release) 1.6 _06 Sun JDK (Windows Production Release) 1.6 _05 Sun JDK (Windows Production Release) 1.6 _04 Sun JDK (Windows Production Release) 1.6 Sun JDK (Windows Production Release) 1.5 0_10 Sun JDK (Windows Production Release) 1.5 _22 Sun JDK (Windows Production Release) 1.5 _18 Sun JDK (Windows Production Release) 1.5 _17 Sun JDK (Windows Production Release) 1.5 _15 Sun JDK (Windows Production Release) 1.5 _14 Sun JDK (Windows Production Release) 1.5 _02 Sun JDK (Windows Production Release) 1.5 _01 Sun JDK (Windows Production Release) 1.5 .0_05 Sun JDK (Windows Production Release) 1.5 .0_04 Sun JDK (Windows Production Release) 1.5 .0_03 Sun JDK (Windows Production Release) 1.4.2 _14 Sun JDK (Windows Production Release) 1.4.2 _09 Sun JDK (Windows Production Release) 1.4.2 _08 Sun JDK (Windows Production Release) 1.4.2 _06 Sun JDK (Windows Production Release) 1.4.2 _05 Sun JDK (Windows Production Release) 1.4.2 _02 Sun JDK (Windows Production Release) 1.4.2 Sun JDK (Windows Production Release) 1.6.0_18 Sun JDK (Windows Production Release) 1.6.0_15 Sun JDK (Windows Production Release) 1.6.0_03 Sun JDK (Windows Production Release) 1.6.0_02 Sun JDK (Windows Production Release) 1.6.0_01-b06 Sun JDK (Windows Production Release) 1.6.0_01 Sun JDK (Windows Production Release) 1.5.0_23 Sun JDK (Windows Production Release) 1.5.0_20 Sun JDK (Windows Production Release) 1.5.0_16 Sun JDK (Windows Production Release) 1.5.0_13 Sun JDK (Windows Production Release) 1.5.0_12 Sun JDK (Windows Production Release) 1.5.0_11-b03 Sun JDK (Windows Production Release) 1.5.0_07-b03 Sun JDK (Windows Production Release) 1.5.0.0_11 Sun JDK (Windows Production Release) 1.5.0.0_09 Sun JDK (Windows Production Release) 1.5.0.0_08 Sun JDK (Windows Production Release) 1.5.0.0_06 Sun JDK (Windows Production Release) 1.4.2_11 Sun JDK (Windows Production Release) 1.4.2_10 Sun JDK (Solaris Production Release) 1.6 _17 Sun JDK (Solaris Production Release) 1.6 _14 Sun JDK (Solaris Production Release) 1.6 _13 Sun JDK (Solaris Production Release) 1.6 _11 Sun JDK (Solaris Production Release) 1.6 _10 Sun JDK (Solaris Production Release) 1.6 _07 Sun JDK (Solaris Production Release) 1.6 _06 Sun JDK (Solaris Production Release) 1.6 _05 Sun JDK (Solaris Production Release) 1.6 _04 Sun JDK (Solaris Production Release) 1.6 _01-b06 Sun JDK (Solaris Production Release) 1.6 Sun JDK (Solaris Production Release) 1.5 0_10 Sun JDK (Solaris Production Release) 1.5 0_09 Sun JDK (Solaris Production Release) 1.5 0_03 Sun JDK (Solaris Production Release) 1.5 _22 Sun JDK (Solaris Production Release) 1.5 _18 Sun JDK (Solaris Production Release) 1.5 _17 Sun JDK (Solaris Production Release) 1.5 _15 Sun JDK (Solaris Production Release) 1.5 _14 Sun JDK (Solaris Production Release) 1.5 _11-b03 Sun JDK (Solaris Production Release) 1.5 _07-b03 Sun JDK (Solaris Production Release) 1.5 _06 Sun JDK (Solaris Production Release) 1.5 _02 Sun JDK (Solaris Production Release) 1.5 _01 Sun JDK (Solaris Production Release) 1.5 .0_05 Sun JDK (Solaris Production Release) 1.5 .0_04 Sun JDK (Solaris Production Release) 1.5 .0_03 Sun JDK (Solaris Production Release) 1.4.2 _14 Sun JDK (Solaris Production Release) 1.4.2 _11 Sun JDK (Solaris Production Release) 1.4.2 _10 Sun JDK (Solaris Production Release) 1.4.2 _09 Sun JDK (Solaris Production Release) 1.4.2 _08 Sun JDK (Solaris Production Release) 1.4.2 _06 Sun JDK (Solaris Production Release) 1.4.2 _05 Sun JDK (Solaris Production Release) 1.4.2 Sun JDK (Solaris Production Release) 1.4.1 _07 Sun JDK (Solaris Production Release) 1.4.1 _01 Sun JDK (Solaris Production Release) 1.4.1 Sun JDK (Solaris Production Release) 1.6.0_18 Sun JDK (Solaris Production Release) 1.6.0_15 Sun JDK (Solaris Production Release) 1.6.0_03 Sun JDK (Solaris Production Release) 1.6.0_02 Sun JDK (Solaris Production Release) 1.6.0_01 Sun JDK (Solaris Production Release) 1.5.0_23 Sun JDK (Solaris Production Release) 1.5.0_20 Sun JDK (Solaris Production Release) 1.5.0_16 Sun JDK (Solaris Production Release) 1.5.0_13 Sun JDK (Solaris Production Release) 1.5.0_12 Sun JDK (Solaris Production Release) 1.5.0_11 Sun JDK (Linux Production Release) 1.6 _17 Sun JDK (Linux Production Release) 1.6 _14 Sun JDK (Linux Production Release) 1.6 _13 Sun JDK (Linux Production Release) 1.6 _11 Sun JDK (Linux Production Release) 1.6 _10 Sun JDK (Linux Production Release) 1.6 _07 Sun JDK (Linux Production Release) 1.6 _06 Sun JDK (Linux Production Release) 1.6 _05 Sun JDK (Linux Production Release) 1.6 _04 Sun JDK (Linux Production Release) 1.6 _01-b06 Sun JDK (Linux Production Release) 1.6 _01 Sun JDK (Linux Production Release) 1.6 Sun JDK (Linux Production Release) 1.5 0_10 Sun JDK (Linux Production Release) 1.5 _22 Sun JDK (Linux Production Release) 1.5 _18 Sun JDK (Linux Production Release) 1.5 _17 Sun JDK (Linux Production Release) 1.5 _15 Sun JDK (Linux Production Release) 1.5 _14 Sun JDK (Linux Production Release) 1.5 _11-b03 Sun JDK (Linux Production Release) 1.5 _07-b03 Sun JDK (Linux Production Release) 1.5 _07 Sun JDK (Linux Production Release) 1.5 _06 Sun JDK (Linux Production Release) 1.5 _02 Sun JDK (Linux Production Release) 1.5 _01 Sun JDK (Linux Production Release) 1.5 .0_05 Sun JDK (Linux Production Release) 1.5 Sun JDK (Linux Production Release) 1.4.2 _14 Sun JDK (Linux Production Release) 1.4.2 _11 Sun JDK (Linux Production Release) 1.4.2 _10 Sun JDK (Linux Production Release) 1.4.2 _09 Sun JDK (Linux Production Release) 1.4.2 _08 Sun JDK (Linux Production Release) 1.4.2 _06 Sun JDK (Linux Production Release) 1.4.2 _05 Sun JDK (Linux Production Release) 1.4.2 Sun JDK (Linux Production Release) 1.6.0_18 Sun JDK (Linux Production Release) 1.6.0_15 Sun JDK (Linux Production Release) 1.6.0_03 Sun JDK (Linux Production Release) 1.6.0_02 Sun JDK (Linux Production Release) 1.5.0_23 Sun JDK (Linux Production Release) 1.5.0_20 Sun JDK (Linux Production Release) 1.5.0_16 Sun JDK (Linux Production Release) 1.5.0_13 Sun JDK (Linux Production Release) 1.5.0.0_12 Sun JDK (Linux Production Release) 1.5.0.0_11 Sun JDK (Linux Production Release) 1.5.0.0_09 Sun JDK (Linux Production Release) 1.5.0.0_08 Sun JDK (Linux Production Release) 1.5.0.0_04 Sun JDK (Linux Production Release) 1.5.0.0_03 S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 Redhat Network Satellite Server (for RHEL 5) 5.3 Redhat Network Satellite Server (for RHEL 4) 5.3 Redhat Enterprise Linux WS Extras 4 Redhat Enterprise Linux WS Extras 3 Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Extras 4 Redhat Enterprise Linux Extras 3 Redhat Enterprise Linux ES Extras 4 Redhat Enterprise Linux ES Extras 3 Redhat Enterprise Linux Desktop Supplementary 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS Extras 4 Redhat Enterprise Linux AS Extras 3 Redhat Enterprise Linux 5 Server Redhat Desktop Extras 4 Redhat Desktop Extras 3 Pardus Linux 2009 0 Oracle JRockit R28.0.0 Oracle JRockit R27.6.6 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 HP Systems Insight Manager C.05.00.02 HP Systems Insight Manager C 05.00.02 HP Systems Insight Manager 6.0.0.96 HP Systems Insight Manager 5.3 Update 1 HP Systems Insight Manager 5.3 HP Systems Insight Manager 5.2 SP2 HP Systems Insight Manager 5.1 SP1 HP Systems Insight Manager 5.0 SP6 HP Systems Insight Manager 5.0 SP5 HP Systems Insight Manager 5.0 SP3 HP Systems Insight Manager 5.0 SP2 HP Systems Insight Manager 5.0 SP1 HP Systems Insight Manager 5.0 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Gentoo Linux Avaya Proactive Contact 3.0.3 Avaya Proactive Contact 3.0.2 Avaya Proactive Contact 3.0 Avaya Aura System Platform 1.0 Apple Mac OS X Server 10.6.3 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac OS X Server 10.5.8 Apple Mac OS X Server 10.5.7 Apple Mac OS X Server 10.5.6 Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.6 Apple Mac OS X Server 10.5 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac OS X 10.5.8 Apple Mac OS X 10.5.7 Apple Mac OS X 10.5.6 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.6 Apple Mac OS X 10.5 |
| Not Vulnerable: |
Sun JRE (Windows Production Release) 1.6.0_19 Sun JRE (Solaris Production Release) 1.6.0_19 Sun JRE (Linux Production Release) 1.6.0_19 Sun JDK (Windows Production Release) 1.5.0_24 Sun JDK (Solaris Production Release) 1.6.0_19 Sun JDK (Solaris Production Release) 1.5.0_24 Sun JDK (Linux Production Release) 1.6.0_19 Sun JDK (Linux Production Release) 1.5.0_24 IBM Java SDK 1.4.2.SR13-FP5 HP Systems Insight Manager 6.1 |
Discussion
Oracle Java SE and Java for Business JRE Trusted Method Chaining Remote Code Execution Vulnerability
Oracle Java SE and Java for Business are prone to a remote code-execution vulnerability affecting the Java Runtime Environment (JRE).
Attackers can exploit this to call trusted methods in an unsafe manner; this can be leveraged to execute arbitrary code with the privileges of the user invoking the JRE.
This vulnerability affects the following supported versions:
6 Update 18, 5.0 Update 23, 1.4.2_25
Oracle Java SE and Java for Business are prone to a remote code-execution vulnerability affecting the Java Runtime Environment (JRE).
Attackers can exploit this to call trusted methods in an unsafe manner; this can be leveraged to execute arbitrary code with the privileges of the user invoking the JRE.
This vulnerability affects the following supported versions:
6 Update 18, 5.0 Update 23, 1.4.2_25
Exploit / POC
Oracle Java SE and Java for Business JRE Trusted Method Chaining Remote Code Execution Vulnerability
A commercial exploit is available through the Immunity Partners program. The exploit was released as part of Immunity's CANVAS Early Update service and is not otherwise publicly available or known to be circulating in the wild.
A Metasploit exploit module is available at the following location:
http://www.metasploit.com/redmine/projects/framework/repository/revisions/10092
A commercial exploit is available through the Immunity Partners program. The exploit was released as part of Immunity's CANVAS Early Update service and is not otherwise publicly available or known to be circulating in the wild.
A Metasploit exploit module is available at the following location:
http://www.metasploit.com/redmine/projects/framework/repository/revisions/10092
Solution / Fix
Oracle Java SE and Java for Business JRE Trusted Method Chaining Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 8.10 powerpc
Ubuntu Ubuntu Linux 9.04 sparc
Ubuntu Ubuntu Linux 9.04 lpia
Ubuntu Ubuntu Linux 8.10 sparc
Ubuntu Ubuntu Linux 9.10 amd64
Mandriva Linux Mandrake 2009.0 x86_64
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 8.10 powerpc
-
Ubuntu openjdk-6-doc_6b12-0ubuntu6.7_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-doc_ 6b12-0ubuntu6.7_all.deb -
Ubuntu openjdk-6-jre-lib_6b12-0ubuntu6.7_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre- lib_6b12-0ubuntu6.7_all.deb -
Ubuntu openjdk-6-source-files_6b12-0ubuntu6.7_all.deb
http://security.ubuntu.com/ubuntu/pool/universe/o/openjdk-6/openjdk-6- source-files_6b12-0ubuntu6.7_all.deb -
Ubuntu openjdk-6-source_6b12-0ubuntu6.7_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-sour ce_6b12-0ubuntu6.7_all.deb
Ubuntu Ubuntu Linux 9.04 sparc
-
Ubuntu openjdk-6-doc_6b14-1.4.1-0ubuntu13_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-doc_ 6b14-1.4.1-0ubuntu13_all.deb -
Ubuntu openjdk-6-jre-lib_6b14-1.4.1-0ubuntu13_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre- lib_6b14-1.4.1-0ubuntu13_all.deb -
Ubuntu openjdk-6-source-files_6b14-1.4.1-0ubuntu13_all.deb
http://security.ubuntu.com/ubuntu/pool/universe/o/openjdk-6/openjdk-6- source-files_6b14-1.4.1-0ubuntu13_all.deb -
Ubuntu openjdk-6-source_6b14-1.4.1-0ubuntu13_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-sour ce_6b14-1.4.1-0ubuntu13_all.deb
Ubuntu Ubuntu Linux 9.04 lpia
-
Ubuntu icedtea-6-jre-cacao_6b14-1.4.1-0ubuntu13_lpia.deb
http://ports.ubuntu.com/pool/main/o/openjdk-6/icedtea-6-jre-cacao_6b14 -1.4.1-0ubuntu13_lpia.deb -
Ubuntu icedtea6-plugin_6b14-1.4.1-0ubuntu13_lpia.deb
http://ports.ubuntu.com/pool/main/o/openjdk-6/icedtea6-plugin_6b14-1.4 .1-0ubuntu13_lpia.deb -
Ubuntu openjdk-6-dbg_6b14-1.4.1-0ubuntu13_lpia.deb
http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-dbg_6b14-1.4.1 -0ubuntu13_lpia.deb -
Ubuntu openjdk-6-demo_6b14-1.4.1-0ubuntu13_lpia.deb
http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-demo_6b14-1.4. 1-0ubuntu13_lpia.deb -
Ubuntu openjdk-6-doc_6b14-1.4.1-0ubuntu13_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-doc_ 6b14-1.4.1-0ubuntu13_all.deb -
Ubuntu openjdk-6-jdk_6b14-1.4.1-0ubuntu13_lpia.deb
http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-jdk_6b14-1.4.1 -0ubuntu13_lpia.deb -
Ubuntu openjdk-6-jre-headless_6b14-1.4.1-0ubuntu13_lpia.deb
http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-jre-headless_6 b14-1.4.1-0ubuntu13_lpia.deb -
Ubuntu openjdk-6-jre-lib_6b14-1.4.1-0ubuntu13_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre- lib_6b14-1.4.1-0ubuntu13_all.deb -
Ubuntu openjdk-6-jre-zero_6b14-1.4.1-0ubuntu13_lpia.deb
http://ports.ubuntu.com/pool/universe/o/openjdk-6/openjdk-6-jre-zero_6 b14-1.4.1-0ubuntu13_lpia.deb -
Ubuntu openjdk-6-jre_6b14-1.4.1-0ubuntu13_lpia.deb
http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-jre_6b14-1.4.1 -0ubuntu13_lpia.deb -
Ubuntu openjdk-6-source-files_6b14-1.4.1-0ubuntu13_all.deb
http://security.ubuntu.com/ubuntu/pool/universe/o/openjdk-6/openjdk-6- source-files_6b14-1.4.1-0ubuntu13_all.deb -
Ubuntu openjdk-6-source_6b14-1.4.1-0ubuntu13_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-sour ce_6b14-1.4.1-0ubuntu13_all.deb
Ubuntu Ubuntu Linux 8.10 sparc
-
Ubuntu icedtea6-plugin_6b12-0ubuntu6.7_sparc.deb
http://ports.ubuntu.com/pool/main/o/openjdk-6/icedtea6-plugin_6b12-0ub untu6.7_sparc.deb -
Ubuntu openjdk-6-dbg_6b12-0ubuntu6.7_sparc.deb
http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-dbg_6b12-0ubun tu6.7_sparc.deb -
Ubuntu openjdk-6-demo_6b12-0ubuntu6.7_sparc.deb
http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-demo_6b12-0ubu ntu6.7_sparc.deb -
Ubuntu openjdk-6-doc_6b12-0ubuntu6.7_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-doc_ 6b12-0ubuntu6.7_all.deb -
Ubuntu openjdk-6-jdk_6b12-0ubuntu6.7_sparc.deb
http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-jdk_6b12-0ubun tu6.7_sparc.deb -
Ubuntu openjdk-6-jre-headless_6b12-0ubuntu6.7_sparc.deb
http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-jre-headless_6 b12-0ubuntu6.7_sparc.deb -
Ubuntu openjdk-6-jre-lib_6b12-0ubuntu6.7_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre- lib_6b12-0ubuntu6.7_all.deb -
Ubuntu openjdk-6-jre_6b12-0ubuntu6.7_sparc.deb
http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-jre_6b12-0ubun tu6.7_sparc.deb -
Ubuntu openjdk-6-source-files_6b12-0ubuntu6.7_all.deb
http://security.ubuntu.com/ubuntu/pool/universe/o/openjdk-6/openjdk-6- source-files_6b12-0ubuntu6.7_all.deb -
Ubuntu openjdk-6-source_6b12-0ubuntu6.7_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-sour ce_6b12-0ubuntu6.7_all.deb
Ubuntu Ubuntu Linux 9.10 amd64
-
Ubuntu icedtea-6-jre-cacao_6b16-1.6.1-3ubuntu3_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/icedtea-6-jre- cacao_6b16-1.6.1-3ubuntu3_amd64.deb -
Ubuntu icedtea6-plugin_6b16-1.6.1-3ubuntu3_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/icedtea6-plugi n_6b16-1.6.1-3ubuntu3_amd64.deb -
Ubuntu openjdk-6-dbg_6b16-1.6.1-3ubuntu3_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-dbg_ 6b16-1.6.1-3ubuntu3_amd64.deb -
Ubuntu openjdk-6-demo_6b16-1.6.1-3ubuntu3_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-demo _6b16-1.6.1-3ubuntu3_amd64.deb -
Ubuntu openjdk-6-doc_6b16-1.6.1-3ubuntu3_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-doc_ 6b16-1.6.1-3ubuntu3_all.deb -
Ubuntu openjdk-6-jdk_6b16-1.6.1-3ubuntu3_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jdk_ 6b16-1.6.1-3ubuntu3_amd64.deb -
Ubuntu openjdk-6-jre-headless_6b16-1.6.1-3ubuntu3_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre- headless_6b16-1.6.1-3ubuntu3_amd64.deb -
Ubuntu openjdk-6-jre-lib_6b16-1.6.1-3ubuntu3_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre- lib_6b16-1.6.1-3ubuntu3_all.deb -
Ubuntu openjdk-6-jre-zero_6b16-1.6.1-3ubuntu3_amd64.deb
http://security.ubuntu.com/ubuntu/pool/universe/o/openjdk-6/openjdk-6- jre-zero_6b16-1.6.1-3ubuntu3_amd64.deb -
Ubuntu openjdk-6-jre_6b16-1.6.1-3ubuntu3_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre_ 6b16-1.6.1-3ubuntu3_amd64.deb -
Ubuntu openjdk-6-source_6b16-1.6.1-3ubuntu3_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-sour ce_6b16-1.6.1-3ubuntu3_all.deb
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva java-1.6.0-openjdk-1.6.0.0-2.b18.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva java-1.6.0-openjdk-demo-1.6.0.0-2.b18.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva java-1.6.0-openjdk-devel-1.6.0.0-2.b18.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva java-1.6.0-openjdk-javadoc-1.6.0.0-2.b18.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva java-1.6.0-openjdk-plugin-1.6.0.0-2.b18.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva java-1.6.0-openjdk-src-1.6.0.0-2.b18.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
References
Oracle Java SE and Java for Business JRE Trusted Method Chaining Remote Code Execution Vulnerability
References:
References:
- HPSBUX02524 SSRT100089 rev.1 - HP-UX Running Java, Remote Execution of Arbitrary (HP)
- Sun's latest Java security alerts (IBM)
- ZDI-10-056: Sun Java Runtime Environment Trusted Methods Chaining Remote Code Ex (Zero Day Initiative)
- ZDI-10-056: Sun Java Runtime Environment Trusted Methods Chaining Remote Code Ex (ZDI Disclosures
) - ASA-2010-088 java-1.6.0-openjdk security update (RHSA-2010-0339) (Avaya)
- ASA-2010-171 HPSBUX02524 SSRT100089 rev.1 - HP-UX Running Java, Remote Execution (Avaya)
- Oracle Critical Patch Update Advisory - July 2010 (Oracle)
- Oracle Java SE and Java for Business Critical Patch Update Advisory - March 2010 (Oracle)