Upstream information
Description
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.NVD CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entries: 777499, 778629, 780897, 785429, 785433, 785814, 798324 SUSE Security Advisories:- SUSE-SU-2012:1231-1, published Tue, 25 Sep 2012 00:09:19 +0200 (CEST)
- SUSE-SU-2012:1398-1, published Wed, 24 Oct 2012 22:08:57 +0200 (CEST)
- openSUSE-SU-2012:1154-1, published Wed, 12 Sep 2012 19:08:39 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SLE 11 SP2 DEBUGINFO |
| sled11-sp2.x86 sled11-sp2.x86-64 SAT Patch Nr: 6772 |
| SUSE Linux Enterprise Desktop 11 SP2 |
| sled11-sp2.x86 sled11-sp2.x86-64 SAT Patch Nr: 6772 |
| SUSE Linux Enterprise Software Development Kit 11 SP2 |
| sles11-sp2.x86 sles11-sp2.x86-64 sles11-sp2-vmware.x86-64 sle11-sp2-sdk.x86-64 sles11-sp2.ppc sle11-sp2-sdk.x86 sles11-sp2.s390x sles11-sp2-vmware.x86 sle11-sp2-sdk.ppc sle11-sp2-sdk.s390x SAT Patch Nr: 6839 |
| SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP2 for VMware |
| sles11-sp2.x86 sles11-sp2.x86-64 sles11-sp2-vmware.x86-64 sle11-sp2-sdk.x86-64 sles11-sp2.ppc sle11-sp2-sdk.x86 sles11-sp2.s390x sles11-sp2-vmware.x86 sle11-sp2-sdk.ppc sle11-sp2-sdk.s390x SAT Patch Nr: 6839 |
| SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP2 for VMware |
| sles11-sp2.x86 sles11-sp2.x86-64 sles11-sp2-vmware.x86-64 sle11-sp2-sdk.x86-64 sles11-sp2.ppc sle11-sp2-sdk.x86 sles11-sp2.s390x sles11-sp2-vmware.x86 sle11-sp2-sdk.ppc sle11-sp2-sdk.s390x SAT Patch Nr: 6839 |
| SUSE Linux Enterprise Server 11 SP2 |
| sles11-sp2.x86 sles11-sp2.x86-64 sles11-sp2-vmware.x86-64 sle11-sp2-sdk.x86-64 sles11-sp2.ppc sle11-sp2-sdk.x86 sles11-sp2.s390x sles11-sp2-vmware.x86 sle11-sp2-sdk.ppc sle11-sp2-sdk.s390x SAT Patch Nr: 6839 |
| SLE 11 SP2 DEBUGINFO |
| sled11-sp2.x86-64 sled11-sp2.x86 SAT Patch Nr: 6987 |
| SUSE Linux Enterprise Desktop 11 SP2 |
| sled11-sp2.x86-64 sled11-sp2.x86 SAT Patch Nr: 6987 |
