~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
PublicDateAtUSN: 2011-02-17
Candidate: CVE-2010-4476
PublicDate: 2011-02-17
References: 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4476
 http://www.oracle.com/technetwork/topics/security/alert-cve-2010-4476-305811.html
 http://www.exploringbinary.com/java-hangs-when-converting-2-2250738585072012e-308/
 http://www.ubuntu.com/usn/usn-1079-1
 http://www.ubuntu.com/usn/usn-1079-2
 http://www.ubuntu.com/usn/usn-1079-3
Description:
 The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle
 Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and
 earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb,
 and other products, allows remote attackers to cause a denial of service
 via a crafted string that triggers an infinite loop of estimations during
 conversion to a double-precision binary floating-point number, as
 demonstrated using 2.2250738585072012e-308.
Ubuntu-Description: 
Notes: 
Bugs: 
 https://bugs.openjdk.java.net/show_bug.cgi?id=100119
 https://bugs.launchpad.net/ubuntu/+source/sun-java6/+bug/716689
Priority: medium
Discovered-by:
Assigned-to: 

Patches_sun-java6:
upstream_sun-java6: released (6.24-1)
dapper_sun-java6: DNE
hardy_sun-java6: released (6.24-1build0.8.04.1)
karmic_sun-java6: released (6.24-1build0.9.10.1)
lucid_sun-java6: released (6.24-1build0.10.04.1)
maverick_sun-java6: released (6.24-1build0.10.10.1)
natty_sun-java6: released (6.24-1build0.10.10.1)
oneiric_sun-java6: not-affected (6.26-1oneiric1)
devel_sun-java6: DNE

Patches_sun-java5:
upstream_sun-java5: needs-triage
dapper_sun-java5: ignored (end of life)
hardy_sun-java5: ignored (upstream sun-java5 is EoL)
karmic_sun-java5: DNE
lucid_sun-java5: DNE
maverick_sun-java5: DNE
natty_sun-java5: DNE
oneiric_sun-java5: DNE
devel_sun-java5: DNE

Patches_openjdk-6:
upstream_openjdk-6: pending (6b22)
dapper_openjdk-6: DNE
hardy_openjdk-6: released (6b27-1.12.3-0ubuntu1~08.04.1)
karmic_openjdk-6: released (6b20-1.9.7-0ubuntu1~9.10.1)
lucid_openjdk-6: released (6b20-1.9.7-0ubuntu1~10.04.1)
maverick_openjdk-6: released (6b20-1.9.7-0ubuntu1)
natty_openjdk-6: released (6b22-1.10-0ubuntu1)
oneiric_openjdk-6: released (6b22-1.10-0ubuntu1)
devel_openjdk-6: released (6b22-1.10-0ubuntu1)

Patches_openjdk-6b18:
upstream_openjdk-6b18: needs-triage
dapper_openjdk-6b18: DNE
hardy_openjdk-6b18: DNE
karmic_openjdk-6b18: released (6b18-1.8.7-0ubuntu1~9.10.1)
lucid_openjdk-6b18: released (6b18-1.8.7-0ubuntu1~10.04.2)
maverick_openjdk-6b18: released (6b18-1.8.7-0ubuntu2.1)
natty_openjdk-6b18: released (6b18-1.8.7-0ubuntu5)
oneiric_openjdk-6b18: released (6b18-1.8.7-0ubuntu5)
devel_openjdk-6b18: released (6b18-1.8.7-0ubuntu5)