Bug 702349 (CVE-2011-0311)

Summary: CVE-2011-0311 IBM JDK Class file parsing denial-of-service
Product: [Other] Security Response Reporter: Marc Schoenefeld <mschoene>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: jrusnack, vdanen
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-02-26 22:37:07 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 701980, 701981, 729588, 729589, 729907, 729908, 729909    
Bug Blocks:    

Description Marc Schoenefeld 2011-05-05 12:28:10 UTC
IBM reported a problem with class file parsing in IBM JDK: 

IBM Runtimes for Java Technology is vulnerable to a denial of service, caused by an error in the class file parser. A remote authenticated attacker could exploit this vulnerability using a specially-crafted class file containing an invalid attribute length field to cause a segmentation fault. [1] 

The issue is fixed with JDK 1.4.2 SR13-FP9 , 5.0 SR12-FP4 and 6 SR9-FP1 [2]
and APAR IZ89602 [3]

[1] http://xforce.iss.net/xforce/xfdb/65189
[2] http://www.ibm.com/developerworks/java/jdk/alerts/
[3] http://www-01.ibm.com/support/docview.wss?uid=swg1IZ89602

Comment 3 errata-xmlrpc 2011-05-05 17:44:45 UTC
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 5
  Extras for RHEL 4

Via RHSA-2011:0490 https://rhn.redhat.com/errata/RHSA-2011-0490.html

Comment 4 errata-xmlrpc 2011-06-15 09:56:16 UTC
This issue has been addressed in following products:

  RHEL 4 for SAP
  RHEL 5 for SAP
  RHEL 6 for SAP

Via RHSA-2011:0870 https://rhn.redhat.com/errata/RHSA-2011-0870.html

Comment 5 errata-xmlrpc 2011-08-15 17:49:43 UTC
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 5
  Extras for RHEL 4

Via RHSA-2011:1159 https://rhn.redhat.com/errata/RHSA-2011-1159.html

Comment 6 errata-xmlrpc 2011-09-06 21:20:12 UTC
This issue has been addressed in following products:

  RHEL 4 for SAP
  RHEL 5 for SAP
  RHEL 6 for SAP

Via RHSA-2011:1265 https://rhn.redhat.com/errata/RHSA-2011-1265.html