Bug 676026 (CVE-2010-4450)

Summary: CVE-2010-4450 OpenJDK Launcher incorrect processing of empty library path entries (6983554)
Product: [Other] Security Response Reporter: Marc Schoenefeld <mschoene>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: ahughes, aph, dbhole, jlieskov, jvanek, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-09-09 02:24:05 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 676274, 676275, 676276, 676277, 676694, 676695, 676696, 688226, 688227, 688228    
Bug Blocks:    

Comment 2 Jan Lieskovsky 2011-02-17 17:06:49 UTC
It was found that the Java launcher provided by OpenJDK did not check the
LD_LIBRARY_PATH environment variable for insecure empty path elements. A local
attacker able to trick a user into running the Java launcher while working from
an attacker-writable directory could use this flaw to load an untrusted
library, subverting the Java security model.

Comment 3 errata-xmlrpc 2011-02-17 18:14:03 UTC
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 5
  Supplementary for Red Hat Enterprise Linux 6
  Extras for RHEL 4

Via RHSA-2011:0282 https://rhn.redhat.com/errata/RHSA-2011-0282.html

Comment 4 errata-xmlrpc 2011-02-17 18:15:40 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5
  Red Hat Enterprise Linux 6

Via RHSA-2011:0281 https://rhn.redhat.com/errata/RHSA-2011-0281.html

Comment 6 errata-xmlrpc 2011-03-17 19:15:29 UTC
This issue has been addressed in following products:

  Extras for RHEL 4
  Supplementary for Red Hat Enterprise Linux 5
  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2011:0364 https://rhn.redhat.com/errata/RHSA-2011-0364.html