Oracle Java SE CVE-2012-0547 Remote Java Runtime Environment Weakness
BID:55339
Info
Oracle Java SE CVE-2012-0547 Remote Java Runtime Environment Weakness
| Bugtraq ID: | 55339 |
| Class: | Unknown |
| CVE: |
CVE-2012-0547 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2012 12:00AM |
| Updated: | Aug 02 2017 06:09PM |
| Credit: | Oracle |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server for VMware 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP2 SuSE SUSE Linux Enterprise Java 11 SP2 SuSE Suse Linux Enterprise Desktop 11 SP2 SuSE Linux Enterprise Software Development Kit 11 SP2 Sun JRE (Linux Production Release) 1.6 _17 Sun JRE (Linux Production Release) 1.6 _13 Sun JRE (Linux Production Release) 1.6 _12 Sun JRE (Linux Production Release) 1.6 _10 Sun JRE (Linux Production Release) 1.6 _07 Sun JRE (Linux Production Release) 1.6 _06 Sun JRE (Linux Production Release) 1.6 _05 Sun JRE (Linux Production Release) 1.6 _04 Sun JRE (Linux Production Release) 1.6 Sun JRE (Linux Production Release) 1.7 Sun JRE (Linux Production Release) 1.6.0_31 Sun JRE (Linux Production Release) 1.6.0_21 Sun JRE (Linux Production Release) 1.6.0_20 Sun JRE (Linux Production Release) 1.6.0_19 Sun JRE (Linux Production Release) 1.6.0_18 Sun JRE (Linux Production Release) 1.6.0_15 Sun JRE (Linux Production Release) 1.6.0_14 Sun JRE (Linux Production Release) 1.6.0_11 Sun JRE (Linux Production Release) 1.6.0_03 Sun JRE (Linux Production Release) 1.6.0_02 Sun JRE (Linux Production Release) 1.6.0_01 Schneider-Electric Trio TView Software 3.27.0 S.u.S.E. openSUSE 12.1 S.u.S.E. openSUSE 11.4 Redhat Network Satellite (for RHEL 6) 5.5 Redhat Network Satellite (for RHEL 5) 5.5 Redhat Enterprise Linux Workstation Supplementary 6 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Server Supplementary 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Supplementary 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Supplementary 6 Redhat Enterprise Linux Desktop Supplementary 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Oracle JRE (Linux Production Release) 1.7.0_4 Oracle JRE (Linux Production Release) 1.7.0_2 Oracle JRE (Linux Production Release) 1.6.0_32 Oracle JRE (Linux Production Release) 1.6.0_30 Oracle JRE (Linux Production Release) 1.6.0_28 Oracle JRE (Linux Production Release) 1.6.0_27 Oracle JRE (Linux Production Release) 1.6.0_26 Oracle JRE (Linux Production Release) 1.6.0_25 Oracle JRE (Linux Production Release) 1.6.0_24 Oracle JRE (Linux Production Release) 1.6.0_23 Oracle JRE (Linux Production Release) 1.6.0_22 Oracle JRE 1.7 Update 6 Oracle JRE 1.6.0 Update 34 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 IBM Java SE 7 SR1 IBM Java SDK 7 SR1 HP NonStop Server J6.0.14.01 HP NonStop Server J06.16 HP NonStop Server J06.15.01 HP NonStop Server J06.15 HP NonStop Server J06.14.02 HP NonStop Server J06.14 HP NonStop Server J06.13.01 HP NonStop Server J06.13 HP NonStop Server J06.12.00 HP NonStop Server J06.11.01 HP NonStop Server J06.11.00 HP NonStop Server J06.10.02 HP NonStop Server J06.10.01 HP NonStop Server J06.10.00 HP NonStop Server J06.09.04 HP NonStop Server J06.09.03 HP NonStop Server J06.09.02 HP NonStop Server J06.09.01 HP NonStop Server J06.09.00 HP NonStop Server J06.08.04 HP NonStop Server J06.08.03 HP NonStop Server J06.08.02 HP NonStop Server J06.08.01 HP NonStop Server J06.08.00 HP NonStop Server J06.07.02 HP NonStop Server J06.07.01 HP NonStop Server J06.07.00 HP NonStop Server J06.06.03 HP NonStop Server J06.06.02 HP NonStop Server J06.06.01 HP NonStop Server J06.06.00 HP NonStop Server J06.05.02 HP NonStop Server J06.05.01 HP NonStop Server J06.05.00 HP NonStop Server J06.04.02 HP NonStop Server J06.04.01 HP NonStop Server J06.04.00 HP NonStop Server H06.27 HP NonStop Server H06.26.01 HP NonStop Server H06.26 HP NonStop Server H06.25.01 HP NonStop Server H06.25 HP NonStop Server H06.24.01 HP NonStop Server H06.24 HP NonStop Server H06.23 HP NonStop Server H06.22.01 HP NonStop Server H06.22.00 HP NonStop Server H06.21.02 HP NonStop Server H06.21.01 HP NonStop Server H06.21.00 HP NonStop Server H06.20.03 HP NonStop Server H06.20.02 HP NonStop Server H06.20.01 HP NonStop Server H06.20.00 HP NonStop Server H06.19.03 HP NonStop Server H06.19.02 HP NonStop Server H06.19.01 HP NonStop Server H06.19.00 HP NonStop Server H06.18.02 HP NonStop Server H06.18.01 HP NonStop Server H06.18.00 HP NonStop Server H06.17.03 HP NonStop Server H06.17.02 HP NonStop Server H06.17.01 HP NonStop Server H06.17.00 HP NonStop Server H06.16.02 HP NonStop Server H06.16.01 HP NonStop Server H06.16.00 HP NonStop Server H06.15.02 HP NonStop Server H06.15.01 HP NonStop Server H06.15.00 HP JDK and JRE 7.0.2 HP JDK and JRE 7.0.1 HP JDK and JRE 7.0 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Hitachi uCosminexus Service Platform 0 Hitachi uCosminexus Service Architect 0 Hitachi uCosminexus Portal Framework 0 Hitachi uCosminexus Operator 0 Hitachi uCosminexus Client 09-00 Hitachi uCosminexus Application Server 09-00 Hitachi Hitachi Processing Kit for XML 0 Hitachi Hitachi HiRDB 8.0 Hitachi Hitachi HiRDB 7.0 Hitachi Cosminexus Studio 4.0 Hitachi Cosminexus 9.0 Hitachi Cosminexus 8.0 Hitachi Cosminexus 7.0 Hitachi Cosminexus 7 Hitachi Cosminexus 6.0 Hitachi Cosminexus 5.0 Gentoo Linux CentOS CentOS 6 CentOS CentOS 5 Avaya Proactive Contact 5.0 Avaya Messaging Application Server 5.0 Avaya Meeting Exchange 5.0 Avaya IQ 5 Avaya IQ 4.0 Avaya IP Office Application Server 8.0 Avaya Call Management System R16.3 Avaya Call Management System R16.2 Avaya Call Management System R16.1 Avaya Call Management System R 16 Avaya Call Management System R 15 Avaya Aura System Manager 6.0 Avaya Aura SIP Enablement Services 5.0 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0.1 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.2 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Communication Manager 5.2.1 SP2 Avaya Aura Application Server 5300 SIP Core 3.0 Avaya Aura Application Server 5300 SIP Core 2.0 Apple Mac OS X Server 10.7 Apple Mac OS X Server 10.6.8 Apple Mac OS X 10.8 Apple Mac OS X 10.7 Apple Mac OS X 10.6.8 |
| Not Vulnerable: |
Schneider-Electric Trio TView Software 3.29.0 Oracle JRE 1.7 Update 7 Oracle JRE 1.6.0 Update 35 IBM Java SE 7 SR2 IBM Java SDK 7 SR2 HP JDK and JRE 7.0.3 |
Discussion
Oracle Java SE CVE-2012-0547 Remote Java Runtime Environment Weakness
Oracle Java SE is prone to a weakness in the Java Runtime Environment.
The issue can be exploited over multiple protocols and affects the 'AWT' sub-component.
Note: The flaw cannot be exploited directly but is dependent on any other security vulnerability that can be directly executed first.
This issue affects the following supported versions:
7 Update 6 and before, 6 Update 34 and before
Oracle Java SE is prone to a weakness in the Java Runtime Environment.
The issue can be exploited over multiple protocols and affects the 'AWT' sub-component.
Note: The flaw cannot be exploited directly but is dependent on any other security vulnerability that can be directly executed first.
This issue affects the following supported versions:
7 Update 6 and before, 6 Update 34 and before
Exploit / POC
Oracle Java SE CVE-2012-0547 Remote Java Runtime Environment Weakness
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Java SE CVE-2012-0547 Remote Java Runtime Environment Weakness
Solution:
Vendor updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
Solution:
Vendor updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
-
Mandriva java-1.6.0-openjdk-1.6.0.0-34.b24.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva java-1.6.0-openjdk-demo-1.6.0.0-34.b24.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva java-1.6.0-openjdk-devel-1.6.0.0-34.b24.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva java-1.6.0-openjdk-javadoc-1.6.0.0-34.b24.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva java-1.6.0-openjdk-src-1.6.0.0-34.b24.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
References
Oracle Java SE CVE-2012-0547 Remote Java Runtime Environment Weakness
References:
References:
- Java Homepage (Sun)
- Multiple Vulnerabilities Cosminexus (Hitachi)
- Oracle Critical Patch Updates (CPUs) and Synchronized Security Releases (SSRs) (IBM)
- Oracle Critical Security Alert for CVE-2012-4681 (Avaya)
- Advisory (ICSA-17-213-02) Schneider Electric Trio TView (CERT)
- APPLE-SA-2012-09-05-1 Java for OS X 2012-005 and Java for Mac OS X 10.6 Update 1 (Apple)
- HPSBNS02920 rev.1 - HP NonStop Servers Multiple Remote Vulnerabilities (HP)
- HPSBUX02824 SSRT100970 rev.1 - HP-UX Running Java, Remote Execution of Arbitrary (HP)
- HPSBUX02825 SSRT100974 rev.1 - HP-UX Running Java, Remote Indirect Vulnerabiliti (HP)
- java-1.6.0-openjdk security update (RHSA-2012-1221) (Avaya)
- Oracle Security Alert for CVE-2012-4681 (Oracle)