An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonzero elements right after the allocation). A remote attacker could use this flaw to obtain potentially sensitive information.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-4420 | third party advisory issue tracking |
https://access.redhat.com/security/cve/cve-2012-4420 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/78693 | third party advisory vdb entry |
http://www.openwall.com/lists/oss-security/2012/09/13/3 | third party advisory mailing list |
http://www.securityfocus.com/bid/55538 | third party advisory vdb entry |
https://www.openwall.com/lists/oss-security/2012/09/12/4 | third party advisory mailing list |
https://bugs.java.com/bugdatabase/view_bug.do?bug_id=7196857 | third party advisory issue tracking exploit |