First published: Thu Jun 07 2012(Updated: )
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java Runtime Environment (JRE) | <=1.5.0 | |
Sun Java Runtime Environment (JRE) | =1.5.0 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update1 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update10 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update11 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update12 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update13 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update14 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update15 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update16 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update17 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update18 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update19 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update2 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update20 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update21 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update22 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update23 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update24 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update25 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update26 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update27 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update28 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update29 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update3 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update31 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update4 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update5 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update6 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update7 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update8 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update9 | |
Oracle Java SE | <=1.6.0 | |
Oracle Java SE | =1.6.0-update22 | |
Oracle Java SE | =1.6.0-update23 | |
Oracle Java SE | =1.6.0-update24 | |
Oracle Java SE | =1.6.0-update25 | |
Oracle Java SE | =1.6.0-update26 | |
Oracle Java SE | =1.6.0-update27 | |
Oracle Java SE | =1.6.0-update29 | |
Sun Java Runtime Environment (JRE) | =1.6.0 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_1 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_10 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_11 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_12 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_13 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_14 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_15 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_16 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_17 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_18 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_19 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_2 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_20 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_21 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_3 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_4 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_5 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_6 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_7 | |
Oracle Java SE | <=1.7.0 | |
Oracle Java SE | =1.7.0 | |
Oracle Java SE | =1.7.0-update1 | |
Oracle Java SE 7 | ||
Sun Java Runtime Environment (JRE) | =1.5.0 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update33 | |
Oracle JRE | =1.6.0-update22 | |
Oracle JRE | =1.6.0-update23 | |
Oracle JRE | =1.6.0-update24 | |
Oracle JRE | =1.6.0-update25 | |
Oracle JRE | =1.6.0-update26 | |
Oracle JRE | =1.6.0-update27 | |
Oracle JRE | =1.6.0-update29 | |
Oracle JRE | =1.6.0-update30 | |
Sun Java Runtime Environment (JRE) | =1.6.0 | |
Oracle JRE | =1.7.0 | |
Oracle JRE | =1.7.0-update1 | |
Oracle JRE | =1.7.0-update2 | |
Debian Linux | =6.0 | |
Debian Linux | =7.0 | |
SUSE Linux Enterprise Desktop | =10-sp4 | |
SUSE Linux Enterprise | =10-sp4 | |
SUSE Linux Enterprise | =11-sp1 | |
SUSE Linux Enterprise Server | =10-sp4 | |
SUSE Linux Enterprise Server | =11-sp1 | |
SUSE Linux Enterprise Server | =11-sp1 | |
SUSE Linux Enterprise Server | =11-sp2 | |
SUSE Linux Enterprise Software Development Kit | =11-sp1 | |
SUSE Linux Enterprise Software Development Kit | =11-sp2 | |
=1.5.0 | ||
=1.5.0-update1 | ||
=1.5.0-update10 | ||
=1.5.0-update11 | ||
=1.5.0-update12 | ||
=1.5.0-update13 | ||
=1.5.0-update14 | ||
=1.5.0-update15 | ||
=1.5.0-update16 | ||
=1.5.0-update17 | ||
=1.5.0-update18 | ||
=1.5.0-update19 | ||
=1.5.0-update2 | ||
=1.5.0-update20 | ||
=1.5.0-update21 | ||
=1.5.0-update22 | ||
=1.5.0-update23 | ||
=1.5.0-update24 | ||
=1.5.0-update25 | ||
=1.5.0-update26 | ||
=1.5.0-update27 | ||
=1.5.0-update28 | ||
=1.5.0-update29 | ||
=1.5.0-update3 | ||
=1.5.0-update31 | ||
=1.5.0-update33 | ||
=1.5.0-update4 | ||
=1.5.0-update5 | ||
=1.5.0-update6 | ||
=1.5.0-update7 | ||
=1.5.0-update8 | ||
=1.5.0-update9 | ||
=1.6.0-update22 | ||
=1.6.0-update23 | ||
=1.6.0-update24 | ||
=1.6.0-update25 | ||
=1.6.0-update26 | ||
=1.6.0-update27 | ||
=1.6.0-update29 | ||
=1.6.0-update30 | ||
=1.6.0 | ||
=1.6.0-update_1 | ||
=1.6.0-update_10 | ||
=1.6.0-update_11 | ||
=1.6.0-update_12 | ||
=1.6.0-update_13 | ||
=1.6.0-update_14 | ||
=1.6.0-update_15 | ||
=1.6.0-update_16 | ||
=1.6.0-update_17 | ||
=1.6.0-update_18 | ||
=1.6.0-update_19 | ||
=1.6.0-update_2 | ||
=1.6.0-update_20 | ||
=1.6.0-update_21 | ||
=1.6.0-update_3 | ||
=1.6.0-update_4 | ||
=1.6.0-update_5 | ||
=1.6.0-update_6 | ||
=1.6.0-update_7 | ||
=1.7.0 | ||
=1.7.0-update1 | ||
=1.7.0-update2 | ||
=6.0 | ||
=7.0 | ||
=10-sp4 | ||
=10-sp4 | ||
=11-sp1 | ||
=10-sp4 | ||
=11-sp1 | ||
=11-sp1 | ||
=11-sp2 | ||
=11-sp1 | ||
=11-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0507 has a severity rating that typically indicates significant potential impact on confidentiality, integrity, and availability.
To address CVE-2012-0507, update your Java Runtime Environment to the latest version provided by Oracle.
CVE-2012-0507 affects Oracle Java SE 7 Update 2 and earlier, as well as multiple older updates of Java 6 and 5.0.
CVE-2012-0507 is an unspecified vulnerability that allows remote attackers to exploit systems running vulnerable Java versions.
If you cannot update due to application compatibility issues, consider implementing strict security measures to mitigate exposure while seeking to address the vulnerabilities.