IBM Runtimes for Java Technology Class File Parser Bug Lets Remote Authenticated Users Deny Service
|
|
SecurityTracker Alert ID: 1025661 |
|
SecurityTracker URL: http://securitytracker.com/id/1025661
|
|
CVE Reference:
CVE-2011-0311
(Links to External Site)
|
Date: Jun 15 2011
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): IBM Runtimes for Java Technology 5.0, 6.0
|
Description:
A vulnerability was reported in IBM Runtimes for Java Technology. A remote authenticated user can cause denial of service conditions.
A remote authenticated user can create a specially crafted class file containing an invalid attribute length field that, when executed, will cause a segmentation fault.
|
Impact:
A remote authenticated user can cause denial of service conditions.
|
Solution:
IBM has issued a fix for IBM Runtimes for Java Technology (IBM JVM).
For Runtimes for Java Technology 5.0:
5.0.0 SR13 or APAR IZ89620.
For Runtimes for Java Technology 6.0:
6.0.0 SR10 or APAR IZ89602.
The IBM advisory is available at:
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ89602
|
Vendor URL: www-01.ibm.com/support/docview.wss?uid=swg1IZ89602 (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
Linux (Any), UNIX (AIX)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Wed, 15 Jun 2011 15:30:12 +0000
Subject: IBM Java JRE JVM
|
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ89602
CVE-2011-0311
|
|