Bug 676019 (CVE-2010-4471)

Summary: CVE-2010-4471 OpenJDK Java2D font-related system property leak (6985453)
Product: [Other] Security Response Reporter: Marc Schoenefeld <mschoene>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: ahughes, aph, dbhole, jvanek, mjc, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-04-11 20:57:54 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 676274, 676275, 676276, 676277, 676694, 676695, 676696, 684826, 684827, 684828, 688226, 688227, 688228    
Bug Blocks: 712887    

Description Marc Schoenefeld 2011-02-08 16:11:03 UTC
A vulnerability was discovered in the 2D subcomponent. Exceptions thrown when processing broken CFF fonts could leak system property values.

This issue (CVE-2010-4471) is not exploitable when using OpenJDK on Red Hat
Enterprise Linux 5 and 6; however, the fix was added as a defense in depth.

Comment 7 errata-xmlrpc 2011-02-17 18:13:56 UTC
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 5
  Supplementary for Red Hat Enterprise Linux 6
  Extras for RHEL 4

Via RHSA-2011:0282 https://rhn.redhat.com/errata/RHSA-2011-0282.html

Comment 8 errata-xmlrpc 2011-02-17 18:15:36 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5
  Red Hat Enterprise Linux 6

Via RHSA-2011:0281 https://rhn.redhat.com/errata/RHSA-2011-0281.html

Comment 10 errata-xmlrpc 2011-03-16 12:37:55 UTC
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 6
  Supplementary for Red Hat Enterprise Linux 5
  Extras for RHEL 4

Via RHSA-2011:0357 https://rhn.redhat.com/errata/RHSA-2011-0357.html

Comment 12 errata-xmlrpc 2011-03-17 19:15:22 UTC
This issue has been addressed in following products:

  Extras for RHEL 4
  Supplementary for Red Hat Enterprise Linux 5
  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2011:0364 https://rhn.redhat.com/errata/RHSA-2011-0364.html

Comment 13 errata-xmlrpc 2011-06-16 19:21:58 UTC
This issue has been addressed in following products:

  Red Hat Network Satellite Server v 5.4

Via RHSA-2011:0880 https://rhn.redhat.com/errata/RHSA-2011-0880.html