Sun JDK JRE SDK 安全特征问题漏洞

漏洞信息详情

Sun JDK JRE SDK 安全特征问题漏洞

漏洞简介

Sun JDK和JRE 6 Update 4以及之前的版本、5.0 Update 14以及之前的版本,SDK和JRE 1.4.2_16以及之前的版本,和1.3.1_21之前的版本下的Java Plug-in中存在安全特征问题漏洞,远程攻击者借助未知向量,绕过相同的原始方针和执行本地应用程序。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Sun JDK 5.0 Update 8

Sun 118666-16

http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -118666-16-1

Sun 118667-16

http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -118667-16-1

Sun 118668-16

http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -118668-16-1

Sun 118669-16

http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -118669-16-1

Sun JDK and JRE 5.0 Update 15

http://java.sun.com/javase/downloads/index_jdk5.jsp

Sun JRE (Windows Production Release) 1.4.2_16

Sun SDK and JRE 1.4.2_17

http://java.sun.com/j2se/1.4.2/download.html

Sun JDK 5.0 Update 7

Sun 118666-16

http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -118666-16-1

Sun 118667-16

http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -118667-16-1

Sun 118668-16

http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -118668-16-1

Sun 118669-16

http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -118669-16-1

Sun JDK and JRE 5.0 Update 15

http://java.sun.com/javase/downloads/index_jdk5.jsp

Sun JDK 6.0 Update 4

Sun 125136-07

http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125136-07-1

Sun 125137-07

http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125137-07-1

Sun 125138-07

http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125138-07-1

Sun 125139-07

http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125139-07-1

Sun JDK and JRE 6 Update 5

http://java.sun.com/javase/downloads/index.jsp

Sun JRE 6.0 Update 2

Sun JDK and JRE 6 Update 5

http://java.sun.com/javase/downloads/index.jsp

参考网址

来源:GENTOO

链接:http://www.gentoo.org/security/en/glsa/glsa-200804-20.xml

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.html

来源:GENTOO

链接:http://www.gentoo.org/security/en/glsa/glsa-200806-11.xml

来源:SECUNIA

链接:http://secunia.com/advisories/29273

来源:CERT

链接:http://www.us-cert.gov/cas/techalerts/TA08-066A.html

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2008/1252

来源:SECUNIA

链接:http://secunia.com/advisories/32018

来源:SECUNIA

链接:http://secunia.com/advisories/30676

来源:SECTRACK

链接:http://www.securitytracker.com/id?1019550

来源:SECUNIA

链接:http://secunia.com/advisories/29897

来源:SECUNIA

链接:http://secunia.com/advisories/29498

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2008-0267.html

来源:XF

链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/41031

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00000.html

来源:SECUNIA

链接:http://secunia.com/advisories/29858

来源:BEA

链接:http://dev2dev.bea.com/pub/advisory/277

来源:SECUNIA

链接:http://secunia.com/advisories/29239

来源:CONFIRM

链接:https://www.vmware.com/security/advisories/VMSA-2008-0010.html

来源:GENTOO

链接:http://security.gentoo.org/glsa/glsa-200804-28.xml

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2008-0186.html

来源:SECUNIA

链接:http://secunia.com/advisories/29582

来源:SECUNIA

链接:http://secunia.com/advisories/30780

来源:SUNALERT

链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-233324-1

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11813

来源:SECUNIA

链接:http://secunia.com/advisories/31497

来源:CONFIRM

链接:http://support.apple.com/kb/HT3179

来源:REDHAT

链接:http://www.redhat.com/support/errata/RHSA-2008-0210.html

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2008/1856/references

来源:CONFIRM

链接:http://www.vmware.com/security/advisories/VMSA-2008-0010.html

来源:SECUNIA

链接:http://secunia.com/advisories/29841

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2008/0770/references

来源:CONFIRM

链接:http://support.apple.com/kb/HT3178

来源:APPLE

链接:http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享