Bug 530098 (CVE-2009-3728)

Summary: CVE-2009-3728 OpenJDK ICC_Profile file existence detection information leak (6631533)
Product: [Other] Security Response Reporter: Marc Schoenefeld <mschoene>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: low    
Version: unspecifiedCC: 229432477, ahughes, bressers, jlieskov, jpechane, kreilly, mjc, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-08-21 22:46:40 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 530367, 530368, 532004, 532005, 534067, 534068    
Bug Blocks:    

Comment 3 Mark J. Cox 2009-11-03 23:06:34 UTC
Available information: 
"ICC_Profile allows detecting if some files exist" 

Interpretation after code inspection.  
  An information leakage vulnerability in the Java Runtime Environment
  with color profiles may allow application to determine the existence 
  of color profile files outside of the ${java.iccprofile.path} directory. 
  This is possible by checking whether the returned
  value of ICC_Profile.getInstance with a returns a null for a given file name
  that has a directory traversal prefix (like ../blabla.pf).

Evaluation: 
  This is a borderline case of information leakage, as the java.io.File class
  allows to aquire the same information easier, and is not limited to color  
  profiles. But as a positive side effect the patch shortens the length of a 
  the privileged block to read the color profile, and reduces the generic 
  attack surface.

Comment 4 errata-xmlrpc 2009-11-09 15:04:44 UTC
This issue has been addressed in following products:

  Extras for RHEL 4
  Extras for Red Hat Enterprise Linux 5

Via RHSA-2009:1560 https://rhn.redhat.com/errata/RHSA-2009-1560.html

Comment 6 errata-xmlrpc 2009-11-10 19:30:27 UTC
This issue has been addressed in following products:

  Extras for RHEL 4
  Extras for Red Hat Enterprise Linux 5

Via RHSA-2009:1571 https://rhn.redhat.com/errata/RHSA-2009-1571.html

Comment 7 Fedora Update System 2009-11-13 08:45:48 UTC
java-1.6.0-openjdk-1.6.0.0-33.b16.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/java-1.6.0-openjdk-1.6.0.0-33.b16.fc12

Comment 8 Fedora Update System 2009-11-13 08:49:43 UTC
java-1.6.0-openjdk-1.6.0.0-23.b16.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/java-1.6.0-openjdk-1.6.0.0-23.b16.fc10

Comment 9 Fedora Update System 2009-11-13 16:34:54 UTC
java-1.6.0-openjdk-1.6.0.0-30.b16.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/java-1.6.0-openjdk-1.6.0.0-30.b16.fc11

Comment 10 Fedora Update System 2009-11-14 03:29:50 UTC
java-1.6.0-openjdk-1.6.0.0-30.b16.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 11 Fedora Update System 2009-11-14 03:31:43 UTC
java-1.6.0-openjdk-1.6.0.0-33.b16.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2009-11-14 03:32:57 UTC
java-1.6.0-openjdk-1.6.0.0-23.b16.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 13 errata-xmlrpc 2009-11-16 15:45:19 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1584 https://rhn.redhat.com/errata/RHSA-2009-1584.html

Comment 14 errata-xmlrpc 2009-12-11 13:43:58 UTC
This issue has been addressed in following products:

  Red Hat Network Satellite Server v 5.1

Via RHSA-2009:1662 https://rhn.redhat.com/errata/RHSA-2009-1662.html