Upstream information

CVE-2005-0836 at MITRE

Description

Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06 allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having critical severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 10
Vector AV:N/AC:L/Au:N/C:C/I:C/A:C
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
SUSE Bugzilla entries: 74219 [CLOSED], 91025 [RESOLVED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE LINUX 9.2
SUSE LINUX 9.3
  • java-1_4_2-sun >= 1.4.2.08-0.1
  • java-1_4_2-sun-alsa >= 1.4.2.08-0.1
  • java-1_4_2-sun-demo >= 1.4.2.08-0.1
  • java-1_4_2-sun-devel >= 1.4.2.08-0.1
  • java-1_4_2-sun-jdbc >= 1.4.2.08-0.1
  • java-1_4_2-sun-plugin >= 1.4.2.08-0.1
  • java-1_4_2-sun-src >= 1.4.2.08-0.1
SuSE Linux Desktop 1.0
  • java2 >= 1.4.2-144
  • java2-jre >= 1.4.2-144
core9.x86
suse91.x86
suse91.ia64
YOU Patch Nr: 10258
Novell Linux Desktop 9 for x86
Novell Linux Desktop 9 for x86_64
Open Enterprise Server
  • java2 >= 1.4.2-129.14
  • java2-jre >= 1.4.2-129.14
core9.x86
suse91.x86
suse91.ia64
YOU Patch Nr: 10258
Open Enterprise Server
  • java2 >= 1.4.2-129.15
  • java2-jre >= 1.4.2-129.15
Builds
YOU Patch Nr: 10267