~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
PublicDateAtUSN: 2012-10-16
Candidate: CVE-2012-5085
PublicDate: 2012-10-16
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5085
 http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html
 http://www.oracle.com/technetwork/topics/security/javacpuoct2012verbose-1515981.html
 http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-October/020571.html
 http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-October/020556.html
 http://www.ubuntu.com/usn/usn-1619-1
Description:
 Unspecified vulnerability in the Java Runtime Environment (JRE) component
 in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0
 Update 36 and earlier, and 1.4.2_38 and earlier allows remote authenticated
 users to have an unspecified impact via unknown vectors related to
 Networking.  NOTE: the Oracle CPU states that this issue has a 0.0 CVSS
 score. If so, then this is not a vulnerability and this issue should not be
 included in CVE.
Ubuntu-Description:
Notes:
 mdeslaur> in lucid+, NetX and the plugin moved to the icedtea-web package
 jdstrand> openjdk-6b18 FTBFS on 11.04 (LP: #1043003)
Bugs:
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=690774
Priority: negligible
Discovered-by:
Assigned-to:

Patches_sun-java6:
upstream_sun-java6: released (6 update 36)
hardy_sun-java6: ignored (upstream version is not redistributable)
lucid_sun-java6: DNE (removed from archive)
natty_sun-java6: DNE (removed from archive)
oneiric_sun-java6: DNE
precise_sun-java6: DNE
quantal_sun-java6: DNE
devel_sun-java6: DNE

Patches_sun-java5:
upstream_sun-java5: ignored (end of life)
hardy_sun-java5: ignored (upstream sun-java5 is EoL)
lucid_sun-java5: DNE
natty_sun-java5: DNE
oneiric_sun-java5: DNE
precise_sun-java5: DNE
quantal_sun-java5: DNE
devel_sun-java5: DNE

Patches_openjdk-6:
upstream_openjdk-6: released (1.10.10, 1.11.5)
hardy_openjdk-6: released (6b27-1.12.3-0ubuntu1~08.04.1)
lucid_openjdk-6: released (6b24-1.11.5-0ubuntu1~10.04.2)
natty_openjdk-6: released (6b24-1.11.5-0ubuntu1~11.04.1)
oneiric_openjdk-6: released (6b24-1.11.5-0ubuntu1~11.10.1)
precise_openjdk-6: released (6b24-1.11.5-0ubuntu1~12.04.1)
quantal_openjdk-6: released (6b24-1.11.5-0ubuntu1~12.10.1)
devel_openjdk-6: released (6b24-1.11.5-0ubuntu1~12.10.1)

Patches_openjdk-6b18:
upstream_openjdk-6b18: released (1.10.10, 1.11.5)
hardy_openjdk-6b18: DNE
lucid_openjdk-6b18: ignored (reached end-of-life)
natty_openjdk-6b18: ignored (reached end-of-life)
oneiric_openjdk-6b18: ignored (superseded by openjdk-6)
precise_openjdk-6b18: DNE
quantal_openjdk-6b18: DNE
devel_openjdk-6b18: DNE

Patches_icedtea-web:
upstream_icedtea-web: needs-triage
hardy_icedtea-web: DNE
lucid_icedtea-web: not-affected
natty_icedtea-web: not-affected
oneiric_icedtea-web: not-affected
precise_icedtea-web: not-affected
quantal_icedtea-web: not-affected
devel_icedtea-web: not-affected

Patches_openjdk-7:
upstream_openjdk-7: released (2.1.3, 2.2.3, 2.3.3)
hardy_openjdk-7: DNE
lucid_openjdk-7: DNE
natty_openjdk-7: DNE
oneiric_openjdk-7: released (7u9-2.3.3-0ubuntu1~11.10.1)
precise_openjdk-7: released (7u9-2.3.3-0ubuntu1~12.04.1)
quantal_openjdk-7: released (7u9-2.3.3-0ubuntu1~12.10.1)
devel_openjdk-7: released (7u9-2.3.3-0ubuntu1~12.10.1)