Insecure deserialization In java-1.6.0-openjdk
Description
A flaw was found in the way the Hotspot component in OpenJDK verified bytecode from the class files. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel7 | 1:1.6.0.34-1.13.6.1.el7_0 | ||
rpm rhel5 | 1:1.7.0.75-2.5.4.0.el5_11 | ||
rpm rhel6 | 1:1.6.0.34-1.13.6.1.el6_6 | ||
rpm rhel6 | 1:1.8.0.31-1.b13.el6_6 | ||
rpm rhel6 | 1:1.7.0.75-2.5.4.0.el6_6 | ||
rpm rhel7 | 1:1.7.0.75-2.5.4.2.el7_0 | ||
rpm rhel5 | 1:1.6.0.34-1.13.6.1.el5_11 |
Aliases
1. 2. 3.