Oracle Java SE and Java for Business CVE-2011-0817 Remote Code Execution Vulnerability
BID:48134
Info
Oracle Java SE and Java for Business CVE-2011-0817 Remote Code Execution Vulnerability
| Bugtraq ID: | 48134 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-0817 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2011 12:00AM |
| Updated: | Mar 19 2015 08:13AM |
| Credit: | Stephen Fewer of Harmony Security |
| Vulnerable: |
SuSE SUSE Linux Enterprise Teradata 10 SP3 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise Server 10 SP3 SuSE SUSE Linux Enterprise SDK 11 SP1 SuSE SUSE Linux Enterprise Java 11 SP1 SuSE SUSE Linux Enterprise Java 10 SP4 SuSE SUSE Linux Enterprise Java 10 SP3 SuSE SUSE Linux Enterprise Desktop 11 SP1 SuSE SUSE Linux Enterprise Desktop 10 SP4 SuSE openSUSE 11.4 SuSE openSUSE 11.3 Sun JRE (Windows Production Release) 1.6 _17 Sun JRE (Windows Production Release) 1.6 _13 Sun JRE (Windows Production Release) 1.6 _12 Sun JRE (Windows Production Release) 1.6 _10 Sun JRE (Windows Production Release) 1.6 _07 Sun JRE (Windows Production Release) 1.6 _06 Sun JRE (Windows Production Release) 1.6 _05 Sun JRE (Windows Production Release) 1.6 _04 Sun JRE (Windows Production Release) 1.6 Sun JRE (Windows Production Release) 1.6.0_25 Sun JRE (Windows Production Release) 1.6.0_24 Sun JRE (Windows Production Release) 1.6.0_23 Sun JRE (Windows Production Release) 1.6.0_22 Sun JRE (Windows Production Release) 1.6.0_21 Sun JRE (Windows Production Release) 1.6.0_20 Sun JRE (Windows Production Release) 1.6.0_2 Sun JRE (Windows Production Release) 1.6.0_19 Sun JRE (Windows Production Release) 1.6.0_18 Sun JRE (Windows Production Release) 1.6.0_15 Sun JRE (Windows Production Release) 1.6.0_14 Sun JRE (Windows Production Release) 1.6.0_11 Sun JRE (Windows Production Release) 1.6.0_03 Sun JRE (Windows Production Release) 1.6.0_02 Sun JRE (Windows Production Release) 1.6.0_01 Sun JDK (Windows Production Release) 1.6 _17 Sun JDK (Windows Production Release) 1.6 _14 Sun JDK (Windows Production Release) 1.6 _13 Sun JDK (Windows Production Release) 1.6 _11 Sun JDK (Windows Production Release) 1.6 _10 Sun JDK (Windows Production Release) 1.6 _07 Sun JDK (Windows Production Release) 1.6 _06 Sun JDK (Windows Production Release) 1.6 _05 Sun JDK (Windows Production Release) 1.6 _04 Sun JDK (Windows Production Release) 1.6 Sun JDK (Windows Production Release) 1.6.0_25 Sun JDK (Windows Production Release) 1.6.0_24 Sun JDK (Windows Production Release) 1.6.0_23 Sun JDK (Windows Production Release) 1.6.0_22 Sun JDK (Windows Production Release) 1.6.0_21 Sun JDK (Windows Production Release) 1.6.0_20 Sun JDK (Windows Production Release) 1.6.0_19 Sun JDK (Windows Production Release) 1.6.0_18 Sun JDK (Windows Production Release) 1.6.0_15 Sun JDK (Windows Production Release) 1.6.0_03 Sun JDK (Windows Production Release) 1.6.0_02 Sun JDK (Windows Production Release) 1.6.0_01-b06 Sun JDK (Windows Production Release) 1.6.0_01 Pardus Linux 2009 0 IBM Java SE 6.0.0 SR9 IBM Java SE 6.0 SR7 IBM Java SE 6.0 SR6 IBM Java SE 6.0 SR5 IBM Java SE 6.0 IBM Java SE 6 SR8 FP1 HP Systems Insight Manager 6.3 HP Systems Insight Manager 6.2 HP Systems Insight Manager 6.1 HP Systems Insight Manager 6.0.0.96 HP Systems Insight Manager 6.0 HP Systems Insight Manager 5.3 Update 1 HP Systems Insight Manager 5.3 HP Systems Insight Manager 5.2 SP2 HP Systems Insight Manager 5.1 SP1 HP Systems Insight Manager 5.0 SP6 HP Systems Insight Manager 5.0 SP5 HP Systems Insight Manager 5.0 SP3 HP Systems Insight Manager 5.0 SP2 HP Systems Insight Manager 5.0 SP1 HP Systems Insight Manager 5.0 HP Systems Insight Manager 4.2 SP2 HP Systems Insight Manager 4.2 SP1 HP Systems Insight Manager 4.2 HP NonStop Server J06.13 HP NonStop Server J06.12.00 HP NonStop Server J06.11.01 HP NonStop Server J06.11.00 HP NonStop Server J06.10.02 HP NonStop Server J06.10.01 HP NonStop Server J06.10.00 HP NonStop Server J06.09.04 HP NonStop Server J06.09.03 HP NonStop Server J06.09.02 HP NonStop Server J06.09.01 HP NonStop Server J06.09.00 HP NonStop Server J06.08.04 HP NonStop Server J06.08.03 HP NonStop Server J06.08.02 HP NonStop Server J06.08.01 HP NonStop Server J06.08.00 HP NonStop Server J06.07.02 HP NonStop Server J06.07.01 HP NonStop Server J06.07.00 HP NonStop Server J06.06.03 HP NonStop Server J06.06.02 HP NonStop Server J06.06.01 HP NonStop Server J06.06.00 HP NonStop Server J06.05.02 HP NonStop Server J06.05.01 HP NonStop Server J06.05.00 HP NonStop Server J06.04.02 HP NonStop Server J06.04.01 HP NonStop Server J06.04.00 HP NonStop Server H06.24 HP NonStop Server H06.23 HP NonStop Server H06.22.01 HP NonStop Server H06.22.00 HP NonStop Server H06.21.02 HP NonStop Server H06.21.01 HP NonStop Server H06.21.00 HP NonStop Server H06.20.03 HP NonStop Server H06.20.02 HP NonStop Server H06.20.01 HP NonStop Server H06.20.00 HP NonStop Server H06.19.03 HP NonStop Server H06.19.02 HP NonStop Server H06.19.01 HP NonStop Server H06.19.00 HP NonStop Server H06.18.02 HP NonStop Server H06.18.01 HP NonStop Server H06.18.00 HP NonStop Server H06.17.03 HP NonStop Server H06.17.02 HP NonStop Server H06.17.01 HP NonStop Server H06.17.00 HP NonStop Server H06.16.02 HP NonStop Server H06.16.01 HP NonStop Server H06.16.00 HP NonStop Server H06.15.02 HP NonStop Server H06.15.01 HP NonStop Server H06.15.00 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 |
| Not Vulnerable: |
Sun JRE (Windows Production Release) 1.6.0_26 Sun JDK (Windows Production Release) 1.6.0_26 IBM Java SE 6.0.0 SR9-FP2 HP Systems Insight Manager 7.0 |
Discussion
Oracle Java SE and Java for Business CVE-2011-0817 Remote Code Execution Vulnerability
Oracle Java SE and Java for Business are prone to a remote code-execution vulnerability in the Java Runtime Environment. The issue occurs because of a NULL pointer dereference error.
The vulnerability can be exploited over multiple protocols.
Attackers can exploit this issue by enticing an unsuspecting user to visit a specially crafted webpage. A successful exploit will result in arbitrary code being executed in the context of the user running the browser. Failed exploit attempts will likely result in denial-of-service conditions.
This vulnerability affects the following supported versions:
6 Update 25
Oracle Java SE and Java for Business are prone to a remote code-execution vulnerability in the Java Runtime Environment. The issue occurs because of a NULL pointer dereference error.
The vulnerability can be exploited over multiple protocols.
Attackers can exploit this issue by enticing an unsuspecting user to visit a specially crafted webpage. A successful exploit will result in arbitrary code being executed in the context of the user running the browser. Failed exploit attempts will likely result in denial-of-service conditions.
This vulnerability affects the following supported versions:
6 Update 25
Exploit / POC
Oracle Java SE and Java for Business CVE-2011-0817 Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Java SE and Java for Business CVE-2011-0817 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Oracle Java SE and Java for Business CVE-2011-0817 Remote Code Execution Vulnerability
References:
References:
- IBM Java Oracle June 7 2011 CPU (IBM)
- Oracle Java SE Critical Patch Update Advisory - June 2011 (Oracle)
- ZDI-11-182 Oracle Java IE Browser Plugin Corrupted Window Procedure Hook Remote (Zero Day Initiative)
- ZDI-11-182: Oracle Java IE Browser Plugin Corrupted Window Procedure Hook Remot (ZDI Disclosures
)