openSUSE Security Update : icedtea-web (openSUSE-SU-2011:0706-1)

This script is Copyright (C) 2014-2016 Tenable Network Security, Inc.


Synopsis :

The remote openSUSE host is missing a security update.

Description :

Icedtea as included in java-1_6_0-openjdk was updated to fix several
security issues :

- S6213702, CVE-2011-0872: (so) non-blocking sockets with
TCP urgent disabled get still selected for read ops
(win)

- S6618658, CVE-2011-0865: Vulnerability in
deserialization

- S7012520, CVE-2011-0815: Heap overflow vulnerability in
FileDialog.show()

- S7013519, CVE-2011-0822, CVE-2011-0862: Integer
overflows in 2D code

- S7013969, CVE-2011-0867: NetworkInterface.toString can
reveal bindings

- S7013971, CVE-2011-0869: Vulnerability in SAAJ

- S7016340, CVE-2011-0870: Vulnerability in SAAJ

- S7016495, CVE-2011-0868: Crash in Java 2D transforming
an image with scale close to zero

- S7020198, CVE-2011-0871: ImageIcon creates Component
with null acc

- S7020373, CVE-2011-0864: JSR rewriting can overflow
memory address size

See also :

http://lists.opensuse.org/opensuse-updates/2011-06/msg00044.html
https://bugzilla.novell.com/show_bug.cgi?id=596177
https://bugzilla.novell.com/show_bug.cgi?id=698739

Solution :

Update the affected icedtea-web packages.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.8
(CVSS2#E:POC/RL:OF/RC:C)
Public Exploit Available : true

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now