Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gain privileges via unspecified vectors, related to an "information leak vulnerability," aka Bug Id 6636650.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11484 | vdb entry signature |
https://bugzilla.redhat.com/show_bug.cgi?id=530173 | |
http://security.gentoo.org/glsa/glsa-200911-02.xml | vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6906 | vdb entry signature |
http://java.sun.com/javase/6/webnotes/6u17.html | vendor advisory |
http://java.sun.com/j2se/1.5.0/ReleaseNotes.html | vendor advisory |
http://www.mandriva.com/security/advisories?name=MDVSA-2010:084 | vendor advisory |
http://secunia.com/advisories/37386 | third party advisory |