Oracle (Sun) Java JRE/JDK 6: Update 26 has critical security vulnerabilities, fixed in Update 29
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Sun Java |
Fix Released
|
Undecided
|
Unassigned | ||
sun-java6 (CentOS) |
Invalid
|
Medium
|
|||
sun-java6 (Debian) |
Fix Released
|
Unknown
|
|||
sun-java6 (Ubuntu) |
Won't Fix
|
Undecided
|
Unassigned |
Bug Description
Release notes from Oracle: http://
Incorporating Security fixes with impact described in http://
"This Critical Patch Update contains 20 new security fixes for Oracle Java SE. 19 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password."
Update 29 provides fixes to current lucid partner 1.6 Update 26 CVE references:
CVE-2011-3548
CVE-2011-3521
CVE-2011-3554
CVE-2011-3544
CVE-2011-3545
CVE-2011-3549
CVE-2011-3551
CVE-2011-3550
CVE-2011-3516
CVE-2011-3556
CVE-2011-3557
CVE-2011-3560
CVE-2011-3555
CVE-2011-3546
CVE-2011-3558
CVE-2011-3547
CVE-2011-3389
CVE-2011-3553
CVE-2011-3552
CVE-2011-3561
Changed in sun-java6 (Debian): | |
status: | Unknown → Fix Released |
summary: |
- Security Update for Sun Java JRE 6: Update 29 + Oracle (Sun) Java JRE/JDK 6: Update 26 has critical security + vulnerabilities, fixed in Update 29 |
Changed in sun-java: | |
status: | Unknown → Fix Released |
Changed in sun-java: | |
importance: | Unknown → Undecided |
status: | Fix Released → New |
status: | New → Fix Released |
Changed in sun-java6 (CentOS): | |
importance: | Unknown → Medium |
status: | Unknown → Invalid |
Update 29 of Oracle/Sun Java fixes an unspecified vulnerability in the Java Runtime Environment (CVE-2011-3555). Upstream has CVSSv2 scored this issue as: 4.0/AV: N/AC:H/ Au:N/C: N/I:P/A: P