DescriptionStefan Cornelius
2012-06-06 14:49:48 UTC
The HotSpot Java Virtual Machine (JVM) field lookup code did not properly check accessibility rules and for static / non-static mismatch. A specially-crafted class file could possibly use this flaw to bypass Java sandbox restrictions.
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2012:0734 https://rhn.redhat.com/errata/RHSA-2012-0734.html