Executive Summary

Informations
NameCVE-2012-0507First vendor Publication2012-06-07
VendorCveLast vendor Modification2013-02-14

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score10Attack RangeNetwork
Cvss Impact Score10Attack ComplexityLow
Cvss Expoit Score10AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0507

CPE : Common Platform Enumeration

TypeDescriptionCount
Application11
Application52

SAINT Exploits

DescriptionLink
Java SE AtomicReferenceArray Unsafe Security BypassMore info here

ExploitDB Exploits

idDescription
2012-03-30Java AtomicReferenceArray Type Violation Vulnerability

Metasploit Database

idDescription
2012-02-14 Java AtomicReferenceArray Type Violation Vulnerability

Internal Sources (Detail)

SourceUrl
BIDhttp://www.securityfocus.com/bid/52161
CONFIRMhttp://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html
https://bugzilla.redhat.com/show_bug.cgi?id=788994
MISChttp://blogs.technet.com/b/mmpc/archive/2012/03/20/an-interesting-case-of-jre...
http://krebsonsecurity.com/2012/03/new-java-attack-rolled-into-exploit-packs/
http://weblog.ikvm.net/PermaLink.aspx?guid=cd48169a-9405-4f63-9087-798c4a1866d3
SECUNIAhttp://secunia.com/advisories/48589
http://secunia.com/advisories/48692
http://secunia.com/advisories/48915
http://secunia.com/advisories/48948
http://secunia.com/advisories/48950

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
DateInformations
2013-05-10 22:33:01
  • Multiple Updates
2013-05-01 17:22:41
  • Multiple Updates
2013-05-01 13:28:09
  • Multiple Updates
2013-05-01 09:22:50
  • Multiple Updates
2013-05-01 05:38:34
  • Multiple Updates
2013-02-15 13:20:26
  • Multiple Updates
2012-12-06 13:20:10
  • Multiple Updates