CVE-2011-3554

NameCVE-2011-3554
DescriptionUnspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-2356-1, DSA-2358-1
NVD severityhigh (attack range: remote)
Debian Bugs645881
Debian/oldoldstablepackage sun-java6 is vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openjdk-6 (PTS)squeeze6b18-1.8.13-0+squeeze2fixed
squeeze (security)6b31-1.13.3-1~deb6u1fixed
squeeze (lts)6b36-1.13.8-1~deb6u1fixed
wheezy6b27-1.12.5-1fixed
wheezy (security)6b36-1.13.8-1~deb7u1fixed
openjdk-7 (PTS)wheezy7u3-2.1.7-1fixed
wheezy (security)7u79-2.5.6-1~deb7u1fixed
stretch, jessie7u75-2.5.4-2fixed
jessie (security)7u79-2.5.6-1~deb8u1fixed
sid7u85-2.6.1-1fixed
sun-java6 (PTS)squeeze/non-free6.26-0squeeze1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
openjdk-6source(unstable)6b23~pre11-1high
openjdk-6sourcelenny6b18-1.8.10-0~lenny2highDSA-2358-1
openjdk-6sourcesqueeze6b18-1.8.10-0+squeeze2highDSA-2356-1
openjdk-7source(unstable)7~b147-2.0-1high
sun-java6source(unstable)(unfixed)high645881

Notes

[lenny] - sun-java6 <no-dsa> (Non-free not supported)
[squeeze] - sun-java6 <no-dsa> (Non-free not supported)

Search for package or bug name: Reporting problems