CVE-2010-0840
Description
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."
Affected products
10cpe:2.3:a:oracle:jre:1.4.2_25:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:jre:1.4.2_25:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:1.5.0:update23:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:1.6.0:update18:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
41- www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlnvdPatchThird Party Advisory
- www.oracle.com/technetwork/topics/security/javacpumar2010-083341.htmlnvdPatchThird Party Advisory
- lists.apple.com/archives/security-announce/2010//May/msg00001.htmlnvdMailing ListThird Party Advisory
- lists.apple.com/archives/security-announce/2010//May/msg00002.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlnvdMailing ListThird Party Advisory
- secunia.com/advisories/39292nvdBroken LinkVendor Advisory
- secunia.com/advisories/39317nvdBroken LinkVendor Advisory
- secunia.com/advisories/39659nvdBroken LinkVendor Advisory
- secunia.com/advisories/39819nvdBroken LinkVendor Advisory
- secunia.com/advisories/40211nvdBroken LinkVendor Advisory
- secunia.com/advisories/40545nvdBroken LinkVendor Advisory
- secunia.com/advisories/43308nvdBroken LinkVendor Advisory
- support.apple.com/kb/HT4170nvdRelease NotesThird Party Advisory
- support.apple.com/kb/HT4171nvdRelease NotesThird Party Advisory
- ubuntu.com/usn/usn-923-1nvdThird Party Advisory
- www.securityfocus.com/archive/1/510528/100/0/threadednvdBroken LinkThird Party AdvisoryVDB Entry
- www.securityfocus.com/archive/1/516397/100/0/threadednvdBroken LinkThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/39065nvdBroken LinkThird Party AdvisoryVDB Entry
- www.vmware.com/security/advisories/VMSA-2011-0003.htmlnvdThird Party Advisory
- www.vupen.com/english/advisories/2010/1191nvdBroken LinkVendor Advisory
- www.vupen.com/english/advisories/2010/1454nvdBroken LinkVendor Advisory
- www.vupen.com/english/advisories/2010/1523nvdBroken LinkVendor Advisory
- www.vupen.com/english/advisories/2010/1793nvdBroken LinkVendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-10-056nvdThird Party AdvisoryVDB Entry
- itrc.hp.com/service/cki/docDisplay.donvdBroken Link
- marc.infonvdMailing List
- marc.infonvdMailing List
- www.mandriva.com/security/advisoriesnvdBroken Link
- www.redhat.com/support/errata/RHSA-2010-0337.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2010-0338.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2010-0339.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2010-0383.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2010-0471.htmlnvdBroken Link
- www.redhat.com/support/errata/RHSA-2010-0489.htmlnvdBroken Link
- www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.htmlnvdRelease Notes
- www.vupen.com/english/advisories/2010/1107nvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13971nvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9974nvdBroken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.