|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2005-0836: Java Web Start JNLP File Command Line Argument Injection Vulnerability | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Masaji Takeyama <takezou040728> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | VERIFIED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Critical | ||
| Priority: | P5 - None | CC: | aj, jason.record, nicole.mooshage, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | All | ||
| Whiteboard: | |||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Masaji Takeyama
2005-03-22 09:48:15 UTC
Please also have a look at bug #63780 - java webstart doesn't work at all due to glibc incompatibilities which we can't fix as we only redistribute prebuilt binaries. I'll prepare updated packages anyway. Reassigning to security team for tracking. (Andreas, any chance to get a new java-1_4_2-sun into 9.3?) More detail. javaws only works with a glibc <= 2.3.2 (according to http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=6188963) and is vulnerable in all 1.4.2 versions <= 1.4.2_06. If I'm not mistaken, this leaves the 8.2 and 9.0 codebases where we need an update. please provide updates only for the codebases which are working. (as discussed) Please teach concretely. Are SUSE 9.0 and SUSE 8.2 discussed? #(javaws only works with a glibc <= 2.3.2) Or, Are SUSE 9.2, 9.1, 9.0, and 8.2 discussed? It already seems to have prepared SUSE 9.3. Update pakeages(It has been released before.): ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/ java2-1.4.2-140.i586.rpm ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/ java2-1.4.2-137.i586.rpm ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/ java2-1.4.2-129.10.i586.rpm ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/ java-1_4_2-sun-1.4.2.06-1.1.i586.rpm P.S. I tested javaws in SUSE 9.1. The javaws works with a glibc-2.3.3 in SUSE 9.1. ( I think that SUSE 9.1 becomes the object of Update. ) #####(Test environment of SUSE 9.1)##### glibc-2.3.3-98 (xorg-x11-libs-6.8.1-14.1) java2-1.4.2-129.10 java2-jre-1.4.2-129.10 # java -version java version "1.4.2_06" Java(TM) 2 Runtime Environment, Standard Edition (build 1.4.2_06-b03) Java HotSpot(TM) Client VM (build 1.4.2_06-b03, mixed mode) ####################### Sonja will do updates. Do we have a fix for this? sonja? why has this been left lying around? CAN-2005-0836 SM-Tracker-1576 Packages submitted. updates and advisory released |