Bug 865531 (CVE-2012-5069)

Summary: CVE-2012-5069 OpenJDK: Executors state handling issues (Concurrency, 7189103)
Product: [Other] Security Response Reporter: Tomas Hoger <thoger>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: ahughes, aph, dbhole, ebaron, jvanek, security-response-team, sgehwolf
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=important,public=20121016,reported=20121011,source=oracle,cvss2=5.8/AV:N/AC:M/Au:N/C:P/I:P/A:N,rhel-5/java-1.6.0-openjdk=affected,rhel-6/java-1.6.0-openjdk=affected,rhel-5/java-1.7.0-openjdk=affected,rhel-6/java-1.7.0-openjdk=affected,rhel-5/java-1.6.0-sun=affected,rhel-6/java-1.6.0-sun=affected,rhel-5/java-1.7.0-oracle=affected,rhel-6/java-1.7.0-oracle=affected,rhel-5/java-1.5.0-ibm=affected,rhel-6/java-1.5.0-ibm=affected,rhel-5/java-1.6.0-ibm=affected,rhel-6/java-1.6.0-ibm=affected,rhel-5/java-1.7.0-ibm=affected,rhel-6/java-1.7.0-ibm=affected
Fixed In Version: icedtea6 1.10.10, icedtea6 1.11.5, icedtea7 2.1.3, icedtea7 2.2.3, icedtea7 2.3.3 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-11-22 14:45:39 EST Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Bug Depends On:    
Bug Blocks: 862579    

Description Tomas Hoger 2012-10-11 13:11:48 EDT
The java.util.concurrent.Executors failed to properly maintain class loader state in the PrivilegedCallableUsingCurrentClassLoader class.  An untrusted Java application or applet could use these flaws to bypass certain Java sandbox restrictions.
Comment 1 Tomas Hoger 2012-10-17 10:40:18 EDT
Fixed now in Oracle JDK 7u9 and 6u37.

External Reference:

http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html
Comment 3 errata-xmlrpc 2012-10-17 12:10:22 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2012:1386 https://rhn.redhat.com/errata/RHSA-2012-1386.html
Comment 4 errata-xmlrpc 2012-10-17 12:11:20 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2012:1385 https://rhn.redhat.com/errata/RHSA-2012-1385.html
Comment 5 errata-xmlrpc 2012-10-17 12:12:15 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2012:1384 https://rhn.redhat.com/errata/RHSA-2012-1384.html
Comment 7 errata-xmlrpc 2012-10-18 12:46:31 EDT
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2012:1391 https://rhn.redhat.com/errata/RHSA-2012-1391.html
Comment 8 errata-xmlrpc 2012-10-18 12:57:11 EDT
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 5
  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2012:1392 https://rhn.redhat.com/errata/RHSA-2012-1392.html
Comment 9 errata-xmlrpc 2012-11-15 16:09:20 EST
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2012:1467 https://rhn.redhat.com/errata/RHSA-2012-1467.html
Comment 10 errata-xmlrpc 2012-11-15 16:10:25 EST
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 6
  Supplementary for Red Hat Enterprise Linux 5

Via RHSA-2012:1465 https://rhn.redhat.com/errata/RHSA-2012-1465.html
Comment 11 errata-xmlrpc 2012-11-15 16:18:55 EST
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 6
  Supplementary for Red Hat Enterprise Linux 5

Via RHSA-2012:1466 https://rhn.redhat.com/errata/RHSA-2012-1466.html
Comment 12 errata-xmlrpc 2013-10-23 12:33:39 EDT
This issue has been addressed in following products:

  Red Hat Network Satellite Server v 5.5

Via RHSA-2013:1456 https://rhn.redhat.com/errata/RHSA-2013-1456.html
Comment 13 errata-xmlrpc 2013-10-23 13:07:37 EDT
This issue has been addressed in following products:

  Red Hat Network Satellite Server v 5.4

Via RHSA-2013:1455 https://rhn.redhat.com/errata/RHSA-2013-1455.html