10

CVE-2012-0507

Warnung
Exploit
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency.  NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions.  NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sun ≫ Jre Version 1.5.0 Update -
Sun ≫ Jre Version 1.5.0 Update update1
Sun ≫ Jre Version 1.5.0 Update update10
Sun ≫ Jre Version 1.5.0 Update update11
Sun ≫ Jre Version 1.5.0 Update update12
Sun ≫ Jre Version 1.5.0 Update update13
Sun ≫ Jre Version 1.5.0 Update update14
Sun ≫ Jre Version 1.5.0 Update update15
Sun ≫ Jre Version 1.5.0 Update update16
Sun ≫ Jre Version 1.5.0 Update update17
Sun ≫ Jre Version 1.5.0 Update update18
Sun ≫ Jre Version 1.5.0 Update update19
Sun ≫ Jre Version 1.5.0 Update update2
Sun ≫ Jre Version 1.5.0 Update update20
Sun ≫ Jre Version 1.5.0 Update update21
Sun ≫ Jre Version 1.5.0 Update update22
Sun ≫ Jre Version 1.5.0 Update update23
Sun ≫ Jre Version 1.5.0 Update update24
Sun ≫ Jre Version 1.5.0 Update update25
Sun ≫ Jre Version 1.5.0 Update update26
Sun ≫ Jre Version 1.5.0 Update update27
Sun ≫ Jre Version 1.5.0 Update update28
Sun ≫ Jre Version 1.5.0 Update update29
Sun ≫ Jre Version 1.5.0 Update update3
Sun ≫ Jre Version 1.5.0 Update update31
Sun ≫ Jre Version 1.5.0 Update update33
Sun ≫ Jre Version 1.5.0 Update update4
Sun ≫ Jre Version 1.5.0 Update update5
Sun ≫ Jre Version 1.5.0 Update update6
Sun ≫ Jre Version 1.5.0 Update update7
Sun ≫ Jre Version 1.5.0 Update update8
Sun ≫ Jre Version 1.5.0 Update update9
Oracle ≫ Jre Version 1.6.0 Update update22
Oracle ≫ Jre Version 1.6.0 Update update23
Oracle ≫ Jre Version 1.6.0 Update update24
Oracle ≫ Jre Version 1.6.0 Update update25
Oracle ≫ Jre Version 1.6.0 Update update26
Oracle ≫ Jre Version 1.6.0 Update update27
Oracle ≫ Jre Version 1.6.0 Update update29
Oracle ≫ Jre Version 1.6.0 Update update30
Sun ≫ Jre Version 1.6.0 Update -
Sun ≫ Jre Version 1.6.0 Update update_1
Sun ≫ Jre Version 1.6.0 Update update_10
Sun ≫ Jre Version 1.6.0 Update update_11
Sun ≫ Jre Version 1.6.0 Update update_12
Sun ≫ Jre Version 1.6.0 Update update_13
Sun ≫ Jre Version 1.6.0 Update update_14
Sun ≫ Jre Version 1.6.0 Update update_15
Sun ≫ Jre Version 1.6.0 Update update_16
Sun ≫ Jre Version 1.6.0 Update update_17
Sun ≫ Jre Version 1.6.0 Update update_18
Sun ≫ Jre Version 1.6.0 Update update_19
Sun ≫ Jre Version 1.6.0 Update update_2
Sun ≫ Jre Version 1.6.0 Update update_20
Sun ≫ Jre Version 1.6.0 Update update_21
Sun ≫ Jre Version 1.6.0 Update update_3
Sun ≫ Jre Version 1.6.0 Update update_4
Sun ≫ Jre Version 1.6.0 Update update_5
Sun ≫ Jre Version 1.6.0 Update update_6
Sun ≫ Jre Version 1.6.0 Update update_7
Oracle ≫ Jre Version 1.7.0 Update -
Oracle ≫ Jre Version 1.7.0 Update update1
Oracle ≫ Jre Version 1.7.0 Update update2
Debian ≫ Debian Linux Version 6.0
Debian ≫ Debian Linux Version 7.0
Suse ≫ Linux Enterprise Desktop Version 10 Update sp4 SwEdition -
Suse ≫ Linux Enterprise Java Version 10 Update sp4
Suse ≫ Linux Enterprise Java Version 11 Update sp1
Suse ≫ Linux Enterprise Server Version 10 Update sp4 SwEdition -
Suse ≫ Linux Enterprise Server Version 11 Update sp1 SwPlatform -
Suse ≫ Linux Enterprise Server Version 11 Update sp1 SwPlatform vmware
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwPlatform -

03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Schwachstelle

An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 98.11% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

http://marc.info/?l=bugtraq&m=134254866602253&w=2
Third Party Advisory
http://marc.info/?l=bugtraq&m=134254957702612&w=2
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html
Third Party Advisory
Issue Tracking
http://marc.info/?l=bugtraq&m=133365109612558&w=2
Third Party Advisory
http://secunia.com/advisories/48692
Broken Link
Not Applicable
http://secunia.com/advisories/48915
Broken Link
Not Applicable
http://secunia.com/advisories/48948
Broken Link
Not Applicable
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00010.html
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=133364885411663&w=2
Third Party Advisory
http://marc.info/?l=bugtraq&m=133847939902305&w=2
Third Party Advisory
http://secunia.com/advisories/48589
Broken Link
Not Applicable
http://secunia.com/advisories/48950
Broken Link
Not Applicable
http://www.debian.org/security/2012/dsa-2420
Third Party Advisory
Mailing List
http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html
Vendor Advisory
http://blogs.technet.com/b/mmpc/archive/2012/03/20/an-interesting-case-of-jre-sandbox-breach-cve-2012-0507.aspx
Third Party Advisory
Broken Link
http://krebsonsecurity.com/2012/03/new-java-attack-rolled-into-exploit-packs/
Third Party Advisory
http://www.securityfocus.com/bid/52161
Third Party Advisory
Exploit
Broken Link
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=788994
Issue Tracking
http://rhn.redhat.com/errata/RHSA-2012-0508.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-0514.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1455.html
Third Party Advisory
http://weblog.ikvm.net/PermaLink.aspx?guid=cd48169a-9405-4f63-9087-798c4a1866d3
Exploit
Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0507
US Government Resource