LWN.net Logo

java-1.6.0-sun: multiple vulnerabilities

Package(s):java-1.6.0-sun CVE #(s):CVE-2008-3105 CVE-2008-3106 CVE-2008-3109 CVE-2008-3110
Created:July 16, 2008 Updated:October 24, 2008
Description:

From the Red Hat advisory:

Several vulnerabilities in the Java API for XML Web Services (JAX-WS) client and service implementation were found. A remote attacker who caused malicious XML to be processed by a trusted or untrusted application was able access URLs or cause a denial of service. (CVE-2008-3105, CVE-2008-3106)

Several vulnerabilities within the JRE scripting support were reported. A remote attacker could grant an untrusted applet extended privileges such as reading and writing local files, executing local programs, or querying the sensitive data of other applets. (CVE-2008-3109, CVE-2008-3110)

Alerts:
Red Hat RHSA-2008:0790-02 2008-07-31
Fedora FEDORA-2008-6439 2008-07-15
Red Hat RHSA-2008:0594-01 2008-07-14
SuSE SUSE-SA:2008:042 2008-08-25
SuSE SUSE-SA:2008:043 2008-09-04
SuSE SUSE-SA:2008:045 2008-09-17
Red Hat RHSA-2008:0906-01 2008-10-24

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds