CVE-2012-1717
Last modified
CVE-2012-1717 is a vulnerability of currently unknown severity. Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows local users to affect confidentiality via unknown vectors related to printing on Solaris or Linux.. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows local users to affect confidentiality via unknown vectors related to printing on Solaris or Linux.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Oracle | Jre | >= 1.4.2, <= 1.4.2_37 | — |
| Oracle | Jre | 1.5.0 | — |
| Oracle | Jre | 1.6.0 | — |
| Oracle | Jre | 1.7.0 | — |
| Oracle | Jdk | >= 1.4.2, <= 1.4.2_37 | — |
| Oracle | Jdk | 1.5.0 | — |
| Oracle | Jdk | 1.6.0 | — |
| Oracle | Jdk | 1.7.0 | — |
| Redhat | Icedtea6 | < 1.10.8 | — |
| Redhat | Icedtea6 | >= 1.11.0, < 1.11.3 | — |
| Redhat | Satellite With Embedded Oracle | 5.5 | — |
| Redhat | Enterprise Linux Desktop | 5.0 | — |
| Redhat | Enterprise Linux Desktop | 6.0 | — |
| Redhat | Enterprise Linux Eus | 6.2 | — |
| Redhat | Enterprise Linux For Ibm Z Systems | 5.0 | — |
| Redhat | Enterprise Linux For Power Big Endian | 5.0 | — |
| Redhat | Enterprise Linux For Scientific Computing | 6.0 | — |
| Redhat | Enterprise Linux Server | 5.0 | — |
| Redhat | Enterprise Linux Server | 6.0 | — |
| Redhat | Enterprise Linux Server Aus | 6.2 | — |
| Redhat | Enterprise Linux Server From Rhui | 6.0 | — |
| Redhat | Enterprise Linux Workstation | 5.0 | — |
| Redhat | Enterprise Linux Workstation | 6.0 | — |
| Suse | Linux Enterprise Desktop | 10 | Sp4 |
| Suse | Linux Enterprise Java | 10 | Sp4 |
| Suse | Linux Enterprise Java | 11 | Sp2 |
| Suse | Linux Enterprise Server | 10 | Sp4 |
| Suse | Linux Enterprise Server | 11 | Sp2 |
| Suse | Linux Enterprise Software Development Kit | 11 | Sp2 |
References
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00020.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00028.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00035.htmlMailing List, Third Party Advisory
- http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0734.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1243.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1455.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1456.htmlThird Party Advisory
- http://secunia.com/advisories/50659Broken Link
- http://secunia.com/advisories/51080Broken Link
- http://security.gentoo.org/glsa/glsa-201406-32.xmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/53952Broken Link, Third Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00020.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00028.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00035.htmlMailing List, Third Party Advisory
- http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0734.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1243.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1455.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1456.htmlThird Party Advisory
- http://secunia.com/advisories/50659Broken Link
- http://secunia.com/advisories/51080Broken Link
- http://security.gentoo.org/glsa/glsa-201406-32.xmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/53952Broken Link, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-1717?
How severe is CVE-2012-1717?
How do I fix CVE-2012-1717?
Are you affected by CVE-2012-1717?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
