Details
The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.Novell Bugzilla entry: 488926,516361 SUSE Security Advisories:
- SUSE-SA:2009:016 , published Fri, 03 Apr 2009 12:00:00 +0000
- SUSE-SA:2009:036 , published Thu, 02 Jul 2009 12:00:00 +0000
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SLES 11 DEBUGINFO |
| sle11-debuginfo. x86-64 sle11-debuginfo. x86-64 sle11-debuginfo. x86 sle11-debuginfo. x86 SAT Patch Nr: 699 |
| SLED 11 |
| sle11-debuginfo. x86-64 sle11-debuginfo. x86-64 sle11-debuginfo. x86 sle11-debuginfo. x86 SAT Patch Nr: 699 |
| SLE 11 |
| sle11. ppc sle11. ia64 sle11. s390x sle11. x86 sle11. x86-64 sle11. s390x sle11. x86-64 sle11. x86 sle11. ppc SAT Patch Nr: 1058 |
| SLE 11 |
| sle11. ppc sle11. ia64 sle11. s390x sle11. x86 sle11. x86-64 sle11. s390x sle11. x86-64 sle11. x86 sle11. ppc SAT Patch Nr: 1058 |
| SLES 11 |
| sle11. ppc sle11. ia64 sle11. s390x sle11. x86 sle11. x86-64 sle11. s390x sle11. x86-64 sle11. x86 sle11. ppc SAT Patch Nr: 1058 |
| SLES 11 |
| sle11. ppc sle11. ia64 sle11. s390x sle11. x86 sle11. x86-64 sle11. s390x sle11. x86-64 sle11. x86 sle11. ppc SAT Patch Nr: 1058 |
| SLES 11 |
| sle11. ppc sle11. ia64 sle11. s390x sle11. x86 sle11. x86-64 sle11. s390x sle11. x86-64 sle11. x86 sle11. ppc SAT Patch Nr: 1058 |
| openSUSE 10.3 |
| ZYPP Patch Nr: 6128 SAT Patch Nr: 705 |
| openSUSE 11.0 |
| ZYPP Patch Nr: 6128 SAT Patch Nr: 705 |
| openSUSE 11.1 |
| ZYPP Patch Nr: 6128 SAT Patch Nr: 705 |