copyright | disclaimer | privacy | contact  
Australia's Leading Computer Emergency Response Team
 
Search this site

 
On this site

 > HOME
 > About AusCERT
 > Membership
 > Contact Us
 > PKI Services
 > Training
 > Publications
 > Sec. Bulletins
 > Conferences
 > News & Media
 > Services
 > Web Log
 > Site Map
 > Site Help
 > Member login





 

ASB-2010.0225 - [Win][UNIX/Linux] Java SE and Java for Business: Unknown/unspecified - Remote/unauthenticated

Date: 13 October 2010
References: ASB-2010.0168  ASB-2010.0222.2  ESB-2010.0928  ESB-2010.0933  ESB-2010.0947  ESB-2010.0949  ESB-2010.0964  ESB-2010.0980  ESB-2010.1033  ESB-2010.1037  
ESB-2010.1093  ESB-2010.1123.3  ESB-2011.0049  ESB-2011.0070  ESB-2011.0086  ESB-2011.0149  ESB-2011.0167.3  ESB-2011.0498  ESB-2011.1090.4  ESB-2012.0336  

Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2010.0225
 Oracle has released a number of updates for Java SE and Java for Business
                              13 October 2010

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Java SE
                      Java for Business
Operating System:     UNIX variants (UNIX, Linux, OSX)
                      Windows
Impact/Access:        Unknown/Unspecified -- Remote/Unauthenticated
Resolution:           Patch/Upgrade
CVE Names:            CVE-2010-3574 CVE-2010-3573 CVE-2010-3572
                      CVE-2010-3571 CVE-2010-3570 CVE-2010-3569
                      CVE-2010-3568 CVE-2010-3567 CVE-2010-3566
                      CVE-2010-3565 CVE-2010-3563 CVE-2010-3562
                      CVE-2010-3561 CVE-2010-3560 CVE-2010-3559
                      CVE-2010-3558 CVE-2010-3557 CVE-2010-3556
                      CVE-2010-3555 CVE-2010-3554 CVE-2010-3553
                      CVE-2010-3552 CVE-2010-3551 CVE-2010-3550
                      CVE-2010-3549 CVE-2010-3548 CVE-2010-3541
                      CVE-2010-1321 CVE-2009-3555 
Member content until: Friday, November 12 2010
Reference:            ASB-2010.0168

OVERVIEW

        Oracle have published information regarding the October 2010 Critical
        Patch Update for Java SE and Java for Business. [1]


IMPACT

        Specific impacts have not been published by Oracle at this time 
        however information on the overall impact has:
        
        "This Critical Patch Update contains 29 new security fixes for
        Oracle Java SE and Java for Business. 28 of these vulnerabilities
        may be remotely exploitable without authentication, i.e., may be
        exploited over a network without the need for a username
        and password." [1]
        
        Oracle advises that the update encompases the following list of CVEs:
        
        CVE-2010-3556
        CVE-2010-3562
        CVE-2010-3565
        CVE-2010-3566
        CVE-2010-3567
        CVE-2010-3571
        CVE-2010-3554
        CVE-2010-3563
        CVE-2010-3568
        CVE-2010-3569
        CVE-2010-3558
        CVE-2010-3552
        CVE-2010-3559
        CVE-2010-3572
        CVE-2010-3553
        CVE-2010-3555
        CVE-2010-3550
        CVE-2010-3570
        CVE-2010-3561
        CVE-2009-3555
        CVE-2010-1321
        CVE-2010-3549
        CVE-2010-3557
        CVE-2010-3541
        CVE-2010-3573
        CVE-2010-3574
        CVE-2010-3548
        CVE-2010-3551
        CVE-2010-3560


MITIGATION

        Administrators responsible for vulnerable products are advised to 
        apply these patches as soon as is practical.


REFERENCES

        [1] Oracle Java SE and Java for Business Critical Patch Update Advisory
            - October 2010
            http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iD8DBQFMtQ/0/iFOrG6YcBERAmOZAJ93+D2R/MIUgKOW5Yqi8B/Xr2lOXQCgj+Gk
EzX4ModdwcKgfZumyhoNc+Y=
=6eEv
-----END PGP SIGNATURE-----