Vulnerability Description
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Jdk | < 1.6.0 |
| Oracle | Jre | < 1.6.0 |
| Canonical | Ubuntu Linux | 10.04 |
| Redhat | Satellite With Embedded Oracle | 5.4 |
| Suse | Linux Enterprise Java | 10 |
| Suse | Linux Enterprise Server | 10 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.htmlMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=132750579901589&w=2Mailing List
- http://marc.info/?l=bugtraq&m=134254866602253&w=2Mailing List
- http://marc.info/?l=bugtraq&m=134254957702612&w=2Mailing List
- http://rhn.redhat.com/errata/RHSA-2013-1455.htmlThird Party Advisory
- http://secunia.com/advisories/48308Broken Link
- http://security.gentoo.org/glsa/glsa-201406-32.xmlThird Party Advisory
- http://www.ibm.com/developerworks/java/jdk/alerts/Product
- http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.htmlPatchVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1384.htmlBroken Link
- http://www.securityfocus.com/bid/50218Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1026215Broken LinkThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-1263-1Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70849Third Party AdvisoryVDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Broken Link
FAQ
What is CVE-2011-3544?
CVE-2011-3544 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java a...
How severe is CVE-2011-3544?
CVE-2011-3544 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2011-3544?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Jdk, Oracle Jre, Canonical Ubuntu Linux, Redhat Satellite With Embedded Oracle, Suse Linux Enterprise Java.