CVE-2011-0872

MEDIUM

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier allows remote attackers to affect availability via unknown vectors related to NIO.

References

http://lists.opensuse.org/opensuse-security-announce/2011-06/msg00003.html

http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00003.html

http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00009.html

http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00001.html

http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00002.html

http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00022.html

http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00025.html

http://marc.info/?l=bugtraq&m=132439520301822&w=2

http://marc.info/?l=bugtraq&m=134254866602253&w=2

http://marc.info/?l=bugtraq&m=134254957702612&w=2

http://secunia.com/advisories/44930

http://security.gentoo.org/glsa/glsa-201406-32.xml

http://support.avaya.com/css/P8/documents/100147041

http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS11-015/index.html

http://www.ibm.com/developerworks/java/jdk/alerts/

http://www.oracle.com/technetwork/topics/security/cpujuly2011-313328.html

http://www.oracle.com/technetwork/topics/security/javacpujune2011-313339.html

http://www.us-cert.gov/cas/techalerts/TA11-201A.html

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14241

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14915

Details

Source: MITRE

Published: 2011-06-14

Updated: 2017-12-22

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:sun:jdk:1.6.0:*:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update1:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update2:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_10:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_11:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_12:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_13:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_14:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_15:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_16:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_17:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_18:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_19:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_20:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_21:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_22:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_23:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_24:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:*:update_25:*:*:*:*:*:* versions up to 1.6.0 (inclusive)

cpe:2.3:a:sun:jdk:1.6.0:update_3:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_4:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_5:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_6:*:*:*:*:*:*

cpe:2.3:a:sun:jdk:1.6.0:update_7:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:*:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_10:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_11:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_12:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_13:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_14:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_15:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_16:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_17:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_18:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_19:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_2:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_20:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_21:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_22:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_23:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_24:*:*:*:*:*:*

cpe:2.3:a:sun:jre:*:update_25:*:*:*:*:*:* versions up to 1.6.0 (inclusive)

cpe:2.3:a:sun:jre:1.6.0:update_3:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_4:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_5:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_6:*:*:*:*:*:*

cpe:2.3:a:sun:jre:1.6.0:update_7:*:*:*:*:*:*

Tenable Plugins

View all (23 total)

IDNameProductFamilySeverity
76303GLSA-201406-32 : IcedTea JDK: Multiple vulnerabilities (BEAST) (ROBOT)NessusGentoo Local Security Checks
critical
75873openSUSE Security Update : java-1_6_0-sun (openSUSE-SU-2011:0633-1)NessusSuSE Local Security Checks
critical
75863openSUSE Security Update : icedtea-web (openSUSE-SU-2011:0706-1)NessusSuSE Local Security Checks
critical
75542openSUSE Security Update : java-1_6_0-sun (openSUSE-SU-2011:0633-1)NessusSuSE Local Security Checks
critical
75527openSUSE Security Update : icedtea-web (openSUSE-SU-2011:0706-1)NessusSuSE Local Security Checks
critical
69874Juniper NSM Servers Multiple Java JDK/JRE Vulnerabilities (PSN-2012-08-689)NessusMisc.
critical
64845Oracle Java SE Multiple Vulnerabilities (June 2011 CPU) (Unix)NessusMisc.
critical
59684HP Systems Insight Manager < 7.0 Multiple VulnerabilitiesNessusWindows
critical
57211SuSE 10 Security Update : Sun/Oracle Java (ZYPP Patch Number 7569)NessusSuSE Local Security Checks
critical
57210SuSE 10 Security Update : IBM Java (ZYPP Patch Number 7627)NessusSuSE Local Security Checks
critical
57207SuSE 10 Security Update : IBM Java (ZYPP Patch Number 7650)NessusSuSE Local Security Checks
critical
57205SuSE 10 Security Update : IBM Java (ZYPP Patch Number 7698)NessusSuSE Local Security Checks
critical
56724GLSA-201111-02 : Oracle JRE/JDK: Multiple vulnerabilities (BEAST)NessusGentoo Local Security Checks
critical
56006SuSE 10 Security Update : IBM Java (ZYPP Patch Number 7697)NessusSuSE Local Security Checks
critical
56004SuSE 11.1 Security Update : IBM Java (SAT Patch Number 5014)NessusSuSE Local Security Checks
critical
56002SuSE9 Security Update : IBM Java JRE and SDK (YOU Patch Number 12819)NessusSuSE Local Security Checks
critical
55768SuSE9 Security Update : IBM Java5 JRE and SDK (YOU Patch Number 12810)NessusSuSE Local Security Checks
critical
55757SuSE 10 Security Update : IBM Java (ZYPP Patch Number 7649)NessusSuSE Local Security Checks
critical
55622SuSE 10 Security Update : IBM Java (ZYPP Patch Number 7626)NessusSuSE Local Security Checks
critical
55619SuSE 11.1 Security Update : IBM Java (SAT Patch Number 4875)NessusSuSE Local Security Checks
critical
55172Ubuntu 10.04 LTS / 10.10 / 11.04 : openjdk-6, openjdk-6b18 vulnerabilities (USN-1154-1)NessusUbuntu Local Security Checks
critical
55137SuSE 11.1 Security Update : Sun/Oracle Java (SAT Patch Number 4698)NessusSuSE Local Security Checks
critical
54997Oracle Java SE Multiple Vulnerabilities (June 2011 CPU)NessusWindows
critical