int(3041)

Vulnerability Bulletins


Escalada de privilegios en Java Dynamic Management Kit

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto con cuenta

System information

Property Value
Affected manufacturer GNU/Linux
Affected software Java Dynamic Management Kit unbundled product 5.1

Description

Se ha descubierto una vulnerabilidad en JMX RMI-II0P API. La vulnerabilidad reside en un error no deseado.

Un atacante local podría tener acceso y ganar privilegios a ciertos datos si un usuario que tenga permisos, accede a ese trabajo.

Solution



Actualización de software

Sun (102835)
Java Dynamic Management Kit unbundled product 5.1 / SPARC / Solaris 8 / JDK 5.0 update 5 / patch 119044-03
Java Dynamic Management Kit unbundled product 5.1 / SPARC / Solaris 9 / JDK 5.0 update 5 / patch 119044-03
Java Dynamic Management Kit unbundled product 5.1 / SPARC / Solaris 10 / JDK 5.0 update 5 / patch 119044-03
JDK <= 1.4 / SPARC / patch 119044-03
Solaris 10 / SPARC / JDK 5.0 update >= 5 / patch 124939-03
JDK <= 1.4 / SPARC / patch 124939-03
Java Dynamic Management Kit unbundled product 5.1 / Solaris 8 / x86 / 5.0 update 5 / patch 119044-03
Java Dynamic Management Kit unbundled product 5.1 / Solaris 9 / x86 / 5.0 update 5 / patch 119044-03
Java Dynamic Management Kit unbundled product 5.1 / Solaris 10 / x86 / 5.0 update 5 / patch 119044-03
JDK <= 1.4 / x86 / patch 119044-03
Solaris 10 / x86 / JDK 5.0 update >= 5 / patch 124939-03
JDK <= 1.4 / x86 / patch 124939-03
Java Dynamic Management Kit 5.1 unbundled product / Windows / JDK 5.0 update 5 / patch 119045-03
JDK <= 1.4 / Windows / patch 119045-03
Java Dynamic Management Kit 5.1 unbundled product / Linux / JDK 5.0 update 5
JDK <= 1.4 / Linux / patch 119046-03
http://java.sun.com/products/archive/

Standar resources

Property Value
CVE
BID

Other resources

Sun Alert Notification (102835)
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102835-1

Version history

Version Comments Date
1.0 Aviso emitido 2007-03-13
Ministerio de Defensa
CNI
CCN
CCN-CERT