Upstream information

CVE-2006-6731 at MITRE

Description

Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflows in the Java_sun_awt_image_ImagingLib_convolveBI, awt_parseRaster, and awt_parseColorModel functions; (2) a stack overflow in the Java_sun_awt_image_ImagingLib_lookupByteRaster function; and (3) improper handling of certain negative values in the Java_sun_font_SunLayoutEngine_nativeLayout function. NOTE: some of these details are obtained from third party information.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having critical severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 9.3
Vector AV:N/AC:M/Au:N/C:C/I:C/A:C
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
SUSE Bugzilla entries: 229905 [RESOLVED / FIXED], 233584 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries
  • IBMJava2-JRE_1_4 >= 1.4.1-23
  • IBMJava2-SDK_1_4 >= 1.4.1-23
ul1.x86-64
ul1.s390
YOU Patch Nr: 11440
SuSE Linux Enterprise Server 8 for IBM zSeries
  • IBMJava2-SDK_1_4 >= 1.4.1-23
ul1.x86-64
ul1.s390
YOU Patch Nr: 11440
SuSE Linux Enterprise Server 8 for AMD64
UnitedLinux 1.0
  • IBMJava2-JRE_1_4 >= 1.4.2-0.4
  • IBMJava2-SDK_1_4 >= 1.4.2-0.4
ul1.x86-64
ul1.s390
YOU Patch Nr: 11440
SUSE LINUX Retail Solution 8
SuSE Linux Enterprise Server 8 for AMD64
SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries
SuSE Linux Openexchange Server 4
SuSE Linux School Server for i386
SuSE Linux Standard Server 8
UnitedLinux 1.0
  • IBMJava2-JRE >= 1.3.1-237
  • IBMJava2-SDK >= 1.3.1-237
slrs8.x86
YOU Patch Nr: 11387
SuSE Linux Desktop 1.0
  • java2 >= 1.4.2-151
  • java2-jre >= 1.4.2-151
slrs8.x86
sles9-oes.x86
YOU Patch Nr: 11368
SUSE LINUX Retail Solution 8
SuSE Linux Enterprise Server 8 for AMD64
SuSE Linux Openexchange Server 4
SuSE Linux School Server for i386
SuSE Linux Standard Server 8
UnitedLinux 1.0
  • java2 >= 1.3.1-696
  • java2-jre >= 1.3.1-696
slrs8.x86
sles9-oes.x86
YOU Patch Nr: 11368
SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries
  • java2 >= 1.3.1-694
  • java2-jre >= 1.3.1-694
slrs8.x86
sles9-oes.x86
YOU Patch Nr: 11368
Novell Linux Desktop 9 for x86
Novell Linux Desktop 9 for x86_64
Open Enterprise Server
  • java2 >= 1.4.2-129.27
  • java2-jre >= 1.4.2-129.27
slrs8.x86
sles9-oes.x86
YOU Patch Nr: 11368
SUSE LINUX 10.0
  • java-1_5_0-sun >= 1.5.0_10-0.1
  • java-1_5_0-sun-alsa >= 1.5.0_10-0.1
  • java-1_5_0-sun-demo >= 1.5.0_10-0.1
  • java-1_5_0-sun-devel >= 1.5.0_10-0.1
  • java-1_5_0-sun-jdbc >= 1.5.0_10-0.1
  • java-1_5_0-sun-plugin >= 1.5.0_10-0.1