VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
JVNDB-2010-001330     ( CVE-2010-0087 | CVE-2010-0087 )
Oracle Sun Java が Java アプレットの署名を正しく検証しない脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001330.html

Original

Oracle Sun Java には、Java アプレットの署名を正しく検証しない脆弱性が存在します。本脆弱性を利用することで、署名の検証時に検知できない形で Java アプレットの改ざんが可能です。

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
JVN iPedia
First Published:
2010-04-23
Source Information Category:
Advisory, Alert
Last Updated:
2010-04-23




Affected Product Tags
cpe:/a:redhat:enterprise_linux:4.7.z:extras
cpe:/a:redhat:enterprise_linux:4.8.z:extras
cpe:/a:redhat:enterprise_linux:4:extras
cpe:/a:redhat:rhel_desktop_supplementary:5::client
cpe:/a:redhat:rhel_supplementary:5::server
cpe:/a:redhat:rhel_supplementary_eus:5.2.z::server
cpe:/a:redhat:rhel_supplementary_eus:5.3.z::server
cpe:/a:redhat:rhel_supplementary_eus:5.4.z::server
cpe:/a:sun:jdk
cpe:/a:sun:jre
cpe:/a:sun:sdk
cpe:/o:misc:miraclelinux_asianux_server:3::x86
cpe:/o:misc:miraclelinux_asianux_server:3::x86-64
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
Medium [?]
X Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

Alternatives
Common Vulnerabilities and Exposures (CVE) CVE-2010-0087




National Vulnerability Database (NVD) CVE-2010-0087








References
Asianux Technical Support Network jdk-1.6.0_19




Critical Patch Updates and Security Alerts javacpumar2010




JVN JVNVU#507652




Red Hat Security Advisory RHSA-2010:0337




Red Hat Security Advisory RHSA-2010:0338




SecurityFocus 39068




US-CERT Vulnerability Note VU#507652




共通脆弱性タイプ一覧 (CWE) 情報不足 (CWE-noinfo)





Copyright © 2010 JPCERT/CC All Rights Reserved.