It was discovered that java.lang.invoke.MethodHandles.Lookup did not properly honor access modes. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
Public now via: http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html Fixed in Oracle Java 7 Update 5. The fix for this issue will be included in the following IcedTea versions: * IcedTea7 2.1.1 * IcedTea7 2.2.1 Patch: http://icedtea.classpath.org/hg/release/icedtea7-forest-2.1/jdk/rev/d2e50959da60
IcedTea7 releases announcement: http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019094.html http://blog.fuseyism.com/index.php/2012/06/13/security-icedtea-2-1-1-2-2-1-released/
This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2012:1019 https://rhn.redhat.com/errata/RHSA-2012-1019.html
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2012:1009 https://rhn.redhat.com/errata/RHSA-2012-1009.html
This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2012:1289 https://rhn.redhat.com/errata/RHSA-2012-1289.html