Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using reflection with a trusted immediate caller to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jdk | Oracle | 1.6.0 (including) | 1.6.0 (including) |
Jdk | Oracle | 1.6.0-update1 (including) | 1.6.0-update1 (including) |
Jdk | Oracle | 1.6.0-update10 (including) | 1.6.0-update10 (including) |
Jdk | Oracle | 1.6.0-update11 (including) | 1.6.0-update11 (including) |
Jdk | Oracle | 1.6.0-update12 (including) | 1.6.0-update12 (including) |
Jdk | Oracle | 1.6.0-update13 (including) | 1.6.0-update13 (including) |
Jdk | Oracle | 1.6.0-update14 (including) | 1.6.0-update14 (including) |
Jdk | Oracle | 1.6.0-update15 (including) | 1.6.0-update15 (including) |
Jdk | Oracle | 1.6.0-update16 (including) | 1.6.0-update16 (including) |
Jdk | Oracle | 1.6.0-update17 (including) | 1.6.0-update17 (including) |
Jdk | Oracle | 1.6.0-update18 (including) | 1.6.0-update18 (including) |
Jdk | Oracle | 1.6.0-update19 (including) | 1.6.0-update19 (including) |
Jdk | Oracle | 1.6.0-update2 (including) | 1.6.0-update2 (including) |
Jdk | Oracle | 1.6.0-update20 (including) | 1.6.0-update20 (including) |
Jdk | Oracle | 1.6.0-update21 (including) | 1.6.0-update21 (including) |
Jdk | Oracle | 1.6.0-update22 (including) | 1.6.0-update22 (including) |
Jdk | Oracle | 1.6.0-update23 (including) | 1.6.0-update23 (including) |
Jdk | Oracle | 1.6.0-update24 (including) | 1.6.0-update24 (including) |
Jdk | Oracle | 1.6.0-update25 (including) | 1.6.0-update25 (including) |
Jdk | Oracle | 1.6.0-update26 (including) | 1.6.0-update26 (including) |
Jdk | Oracle | 1.6.0-update27 (including) | 1.6.0-update27 (including) |
Jdk | Oracle | 1.6.0-update29 (including) | 1.6.0-update29 (including) |
Jdk | Oracle | 1.6.0-update3 (including) | 1.6.0-update3 (including) |
Jdk | Oracle | 1.6.0-update30 (including) | 1.6.0-update30 (including) |
Jdk | Oracle | 1.6.0-update31 (including) | 1.6.0-update31 (including) |
Jdk | Oracle | 1.6.0-update32 (including) | 1.6.0-update32 (including) |
Jdk | Oracle | 1.6.0-update33 (including) | 1.6.0-update33 (including) |
Jdk | Oracle | 1.6.0-update34 (including) | 1.6.0-update34 (including) |
Jdk | Oracle | 1.6.0-update4 (including) | 1.6.0-update4 (including) |
Jdk | Oracle | 1.6.0-update5 (including) | 1.6.0-update5 (including) |
Jdk | Oracle | 1.6.0-update6 (including) | 1.6.0-update6 (including) |
Jdk | Oracle | 1.6.0-update7 (including) | 1.6.0-update7 (including) |
Jdk | Oracle | 1.6.0-update8 (including) | 1.6.0-update8 (including) |
Jdk | Oracle | 1.6.0-update9 (including) | 1.6.0-update9 (including) |
Jdk | Oracle | 1.7.0 (including) | 1.7.0 (including) |
Jdk | Oracle | 1.7.0-update1 (including) | 1.7.0-update1 (including) |
Jdk | Oracle | 1.7.0-update2 (including) | 1.7.0-update2 (including) |
Jdk | Oracle | 1.7.0-update3 (including) | 1.7.0-update3 (including) |
Jdk | Oracle | 1.7.0-update4 (including) | 1.7.0-update4 (including) |
Jdk | Oracle | 1.7.0-update5 (including) | 1.7.0-update5 (including) |
Jdk | Oracle | 1.7.0-update6 (including) | 1.7.0-update6 (including) |
Jre | Oracle | 1.6.0 (including) | 1.6.0 (including) |
Jre | Oracle | 1.6.0-update1 (including) | 1.6.0-update1 (including) |
Jre | Oracle | 1.6.0-update10 (including) | 1.6.0-update10 (including) |
Jre | Oracle | 1.6.0-update11 (including) | 1.6.0-update11 (including) |
Jre | Oracle | 1.6.0-update12 (including) | 1.6.0-update12 (including) |
Jre | Oracle | 1.6.0-update13 (including) | 1.6.0-update13 (including) |
Jre | Oracle | 1.6.0-update14 (including) | 1.6.0-update14 (including) |
Jre | Oracle | 1.6.0-update15 (including) | 1.6.0-update15 (including) |
Jre | Oracle | 1.6.0-update16 (including) | 1.6.0-update16 (including) |
Jre | Oracle | 1.6.0-update17 (including) | 1.6.0-update17 (including) |
Jre | Oracle | 1.6.0-update18 (including) | 1.6.0-update18 (including) |
Jre | Oracle | 1.6.0-update19 (including) | 1.6.0-update19 (including) |
Jre | Oracle | 1.6.0-update2 (including) | 1.6.0-update2 (including) |
Jre | Oracle | 1.6.0-update20 (including) | 1.6.0-update20 (including) |
Jre | Oracle | 1.6.0-update21 (including) | 1.6.0-update21 (including) |
Jre | Oracle | 1.6.0-update22 (including) | 1.6.0-update22 (including) |
Jre | Oracle | 1.6.0-update23 (including) | 1.6.0-update23 (including) |
Jre | Oracle | 1.6.0-update24 (including) | 1.6.0-update24 (including) |
Jre | Oracle | 1.6.0-update25 (including) | 1.6.0-update25 (including) |
Jre | Oracle | 1.6.0-update26 (including) | 1.6.0-update26 (including) |
Jre | Oracle | 1.6.0-update27 (including) | 1.6.0-update27 (including) |
Jre | Oracle | 1.6.0-update29 (including) | 1.6.0-update29 (including) |
Jre | Oracle | 1.6.0-update3 (including) | 1.6.0-update3 (including) |
Jre | Oracle | 1.6.0-update30 (including) | 1.6.0-update30 (including) |
Jre | Oracle | 1.6.0-update31 (including) | 1.6.0-update31 (including) |
Jre | Oracle | 1.6.0-update32 (including) | 1.6.0-update32 (including) |
Jre | Oracle | 1.6.0-update33 (including) | 1.6.0-update33 (including) |
Jre | Oracle | 1.6.0-update34 (including) | 1.6.0-update34 (including) |
Jre | Oracle | 1.6.0-update4 (including) | 1.6.0-update4 (including) |
Jre | Oracle | 1.6.0-update5 (including) | 1.6.0-update5 (including) |
Jre | Oracle | 1.6.0-update6 (including) | 1.6.0-update6 (including) |
Jre | Oracle | 1.6.0-update7 (including) | 1.6.0-update7 (including) |
Jre | Oracle | 1.6.0-update9 (including) | 1.6.0-update9 (including) |
Jre | Oracle | 1.7.0 (including) | 1.7.0 (including) |
Jre | Oracle | 1.7.0-update1 (including) | 1.7.0-update1 (including) |
Jre | Oracle | 1.7.0-update2 (including) | 1.7.0-update2 (including) |
Jre | Oracle | 1.7.0-update3 (including) | 1.7.0-update3 (including) |
Jre | Oracle | 1.7.0-update4 (including) | 1.7.0-update4 (including) |
Jre | Oracle | 1.7.0-update5 (including) | 1.7.0-update5 (including) |
Jre | Oracle | 1.7.0-update6 (including) | 1.7.0-update6 (including) |
Red Hat Enterprise Linux 6 | RedHat | java-1.7.0-openjdk-1:1.7.0.5-2.2.1.el6_3.3 | * |
Supplementary for Red Hat Enterprise Linux 6 | RedHat | java-1.7.0-oracle-1:1.7.0.7-1jpp.5.el6_3 | * |
Supplementary for Red Hat Enterprise Linux 6 | RedHat | java-1.7.0-ibm-1:1.7.0.2.0-1jpp.3.el6_3 | * |
Openjdk-6 | Ubuntu | hardy | * |
Openjdk-7 | Ubuntu | oneiric | * |
Sun-java5 | Ubuntu | hardy | * |
Sun-java6 | Ubuntu | hardy | * |