|
Sun JES / Solaris OpenSSL RSA Signature Forgery
|
|
Secunia Advisory:
|
SA22585
|
|
|
Release Date:
|
2006-10-26
|
|
Popularity:
|
7,666 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Security Bypass
|
|
Where:
|
From remote
|
|
Solution Status:
|
Partial Fix
|
|
| OS: | Sun Solaris 10 Sun Solaris 9
|
|
| Software: | Sun Java Enterprise System 2003Q4 Sun Java Enterprise System 2004Q2 Sun Java Enterprise System 2005Q1 Sun Java Enterprise System 2005Q4
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2006-4339
|
|
Description: Sun has acknowledged a vulnerability in Sun Java Enterprise System and Solaris, which potentially can be exploited by malicious people to bypass certain security restrictions.
For more information:
SA21709
The following versions are affected:
* Sun Solaris 9
* Sun Solaris 10
* Sun Java Enterprise System 2003Q4
* Sun Java Enterprise System 2004Q2
* Sun Java Enterprise System 2005Q1
* Sun Java Enterprise System 2005Q4
Solution: Apply patches.
-- SPARC Platform --
Solaris 10:
Apply patch 119213-10 or later.
Sun Java Enterprise System 2004Q2, 2005Q1 and 2005Q4 for Solaris 8:
Apply patch 119209-10 or later.
Sun Java Enterprise System 2004Q2, 2005Q1 and 2005Q4 for Solaris 9:
Apply patch 119211-10 or later.
Sun Java Enterprise System 2005Q1 and 2005Q4 for Solaris 10:
Apply patch 119213-10 or later.
-- x86 Platform --
Solaris 10:
Apply patch 119214-10 or later.
Sun Java Enterprise System 2004Q2, 2005Q1 and 2005Q4 for Solaris 9:
Apply patch 119212-10 or later.
Sun Java Enterprise System 2005Q1 and 2005Q4 for Solaris 10:
Apply patch 119214-10 or later.
-- Linux Platform --
Sun Java Enterprise System 2003Q4, 2004Q2, 2005Q1 and 2005Q4 for Linux:
Apply patch 121656-10 or later.
-- HP-UX Platform --
Sun Java Enterprise System 2005Q1 and 2005Q4 for HP-UX:
Apply patch 124379-01 or later.
For some versions a final resolution is pending completion.
Original Advisory: http://sunsolve.sun.com/search/docume...setkey=1-26-102656-1&searchclause
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|