Bug 702349 (CVE-2011-0311) - CVE-2011-0311 IBM JDK Class file parsing denial-of-service
Summary: CVE-2011-0311 IBM JDK Class file parsing denial-of-service
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2011-0311
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 701980 701981 729588 729589 729907 729908 729909
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-05-05 12:28 UTC by Marc Schoenefeld
Modified: 2019-09-29 12:44 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-02-26 22:37:07 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2011:0490 0 normal SHIPPED_LIVE Critical: java-1.4.2-ibm security update 2011-05-05 17:44:32 UTC
Red Hat Product Errata RHSA-2011:0870 0 normal SHIPPED_LIVE Moderate: java-1.4.2-ibm-sap security update 2011-06-15 09:56:03 UTC
Red Hat Product Errata RHSA-2011:1159 0 normal SHIPPED_LIVE Critical: java-1.4.2-ibm security update 2011-08-15 17:49:36 UTC
Red Hat Product Errata RHSA-2011:1265 0 normal SHIPPED_LIVE Moderate: java-1.4.2-ibm-sap security update 2011-09-06 21:20:08 UTC

Description Marc Schoenefeld 2011-05-05 12:28:10 UTC
IBM reported a problem with class file parsing in IBM JDK: 

IBM Runtimes for Java Technology is vulnerable to a denial of service, caused by an error in the class file parser. A remote authenticated attacker could exploit this vulnerability using a specially-crafted class file containing an invalid attribute length field to cause a segmentation fault. [1] 

The issue is fixed with JDK 1.4.2 SR13-FP9 , 5.0 SR12-FP4 and 6 SR9-FP1 [2]
and APAR IZ89602 [3]

[1] http://xforce.iss.net/xforce/xfdb/65189
[2] http://www.ibm.com/developerworks/java/jdk/alerts/
[3] http://www-01.ibm.com/support/docview.wss?uid=swg1IZ89602

Comment 3 errata-xmlrpc 2011-05-05 17:44:45 UTC
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 5
  Extras for RHEL 4

Via RHSA-2011:0490 https://rhn.redhat.com/errata/RHSA-2011-0490.html

Comment 4 errata-xmlrpc 2011-06-15 09:56:16 UTC
This issue has been addressed in following products:

  RHEL 4 for SAP
  RHEL 5 for SAP
  RHEL 6 for SAP

Via RHSA-2011:0870 https://rhn.redhat.com/errata/RHSA-2011-0870.html

Comment 5 errata-xmlrpc 2011-08-15 17:49:43 UTC
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 5
  Extras for RHEL 4

Via RHSA-2011:1159 https://rhn.redhat.com/errata/RHSA-2011-1159.html

Comment 6 errata-xmlrpc 2011-09-06 21:20:12 UTC
This issue has been addressed in following products:

  RHEL 4 for SAP
  RHEL 5 for SAP
  RHEL 6 for SAP

Via RHSA-2011:1265 https://rhn.redhat.com/errata/RHSA-2011-1265.html


Note You need to log in before you can comment on or make changes to this bug.