Index: vuln.xml =================================================================== RCS file: /home/pcvs/ports/security/vuxml/vuln.xml,v retrieving revision 1.1166 diff -u -r1.1166 vuln.xml --- vuln.xml 4 Oct 2006 10:27:16 -0000 1.1166 +++ vuln.xml 4 Oct 2006 16:40:26 -0000 @@ -34,6 +34,62 @@ --> + + jdk -- RSA Signature Forgery Vulnerability + + + jdk + 1.3 + 1.3.*1.4 + 1.4.*1.5 + 1.5.*1.6 + + + linux-sun-jdk + 1.3 + 1.3.*1.4 + 1.4.*1.5 + 1.5.*1.6 + + + diablo-jdk + diablo-jre + 1.5.0.09 + + + diablo-jdk-freebsd6 + linux-jdk + 0 + + + + +

Secunia reports:

+
+

Sun has acknowledged a vulnerability in Sun JDK/SDK, which + potentially can be exploited by malicious people to bypass + certain security restrictions.

+

The following products are affected:

+
    +
  • JDK and JRE 5.0 Update 8 and earlier
  • +
  • SDK and JRE 1.4.2_12 and earlier
  • +
  • SDK and JRE 1.3.1_19 and earlier
  • +
  • JSSE 1.0.3_03 and earlier
  • +
+
+ +
+ + CVE-2006-4339 + http://secunia.com/advisories/22204/ + http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1 + + + 2006-10-02 + 2006-10-04 + +
+ postnuke -- admin section SQL injection