~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
PublicDateAtUSN: 2012-10-16
Candidate: CVE-2012-1531
PublicDate: 2012-10-16
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1531
 http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html
 http://www.ubuntu.com/usn/usn-1619-1
Description:
 Unspecified vulnerability in the Java Runtime Environment (JRE) component
 in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0
 Update 36 and earlier, and 1.4.2_38 and earlier; and JavaFX 2.2 and
 earlier; allows remote attackers to affect confidentiality, integrity, and
 availability via unknown vectors related to 2D.
Ubuntu-Description:
Notes:
 mdeslaur> in lucid+, NetX and the plugin moved to the icedtea-web package
 jdstrand> openjdk-6b18 FTBFS on 11.04 (LP: #1043003)
 jdstrand> http://rhn.redhat.com/errata/RHSA-2013-1467.html states this is
  Oracle JDK only, but based on Oracle advisory we claimed it was fixed in
  http://www.ubuntu.com/usn/usn-1619-1.
Bugs:
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=690774
Priority: medium
Discovered-by:
Assigned-to:

Patches_sun-java6:
upstream_sun-java6: released (6 update 36)
hardy_sun-java6: ignored (upstream version is not redistributable)
lucid_sun-java6: DNE (removed from archive)
natty_sun-java6: DNE (removed from archive)
oneiric_sun-java6: DNE
precise_sun-java6: DNE
quantal_sun-java6: DNE
devel_sun-java6: DNE

Patches_sun-java5:
upstream_sun-java5: released (5.0 update 37)
hardy_sun-java5: ignored (upstream sun-java5 is EoL)
lucid_sun-java5: DNE
natty_sun-java5: DNE
oneiric_sun-java5: DNE
precise_sun-java5: DNE
quantal_sun-java5: DNE
devel_sun-java5: DNE

Patches_openjdk-6:
upstream_openjdk-6: released (6 update 36)
hardy_openjdk-6: released (6b27-1.12.3-0ubuntu1~08.04.1)
lucid_openjdk-6: released (6b24-1.11.5-0ubuntu1~10.04.2)
natty_openjdk-6: released (6b24-1.11.5-0ubuntu1~11.04.1)
oneiric_openjdk-6: released (6b24-1.11.5-0ubuntu1~11.10.1)
precise_openjdk-6: released (6b24-1.11.5-0ubuntu1~12.04.1)
quantal_openjdk-6: released (6b24-1.11.5-0ubuntu1~12.10.1)
devel_openjdk-6: released (6b24-1.11.5-0ubuntu1~12.10.1)

Patches_openjdk-6b18:
upstream_openjdk-6b18: needs-triage
hardy_openjdk-6b18: DNE
lucid_openjdk-6b18: ignored (reached end-of-life)
natty_openjdk-6b18: ignored (reached end-of-life)
oneiric_openjdk-6b18: ignored (superseded by openjdk-6)
precise_openjdk-6b18: DNE
quantal_openjdk-6b18: DNE
devel_openjdk-6b18: DNE

Patches_icedtea-web:
upstream_icedtea-web: needs-triage
hardy_icedtea-web: DNE
lucid_icedtea-web: not-affected
natty_icedtea-web: not-affected
oneiric_icedtea-web: not-affected
precise_icedtea-web: not-affected
quantal_icedtea-web: not-affected
devel_icedtea-web: not-affected

Patches_openjdk-7:
upstream_openjdk-7: released (7 update 8)
hardy_openjdk-7: DNE
lucid_openjdk-7: DNE
natty_openjdk-7: DNE
oneiric_openjdk-7: released (7u9-2.3.3-0ubuntu1~11.10.1)
precise_openjdk-7: released (7u9-2.3.3-0ubuntu1~12.04.1)
quantal_openjdk-7: released (7u9-2.3.3-0ubuntu1~12.10.1)
devel_openjdk-7: released (7u9-2.3.3-0ubuntu1~12.10.1)