{
  "cves": [
    "CVE-2011-3544",
    "CVE-2011-3551",
    "CVE-2011-3554",
    "CVE-2011-3556",
    "CVE-2011-3389",
    "CVE-2011-3557",
    "CVE-2011-3521",
    "CVE-2011-3547",
    "CVE-2011-3548",
    "CVE-2011-3552",
    "CVE-2011-3553",
    "CVE-2011-3558",
    "CVE-2011-3560"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "CRITICAL"
  },
  "description": "[1:1.6.0.0-1.40.1.9.10]\n- Resolves: rhbz#744788\n- Bumped to IcedTea6 1.9.8\n-removed font copying\n Security fixes\n  - S7000600, CVE-2011-3547: InputStream skip() information leak\n  - S7019773, CVE-2011-3548: mutable static AWTKeyStroke.ctor\n  - S7023640, CVE-2011-3551: Java2D TransformHelper integer overflow\n  - S7032417, CVE-2011-3552: excessive default UDP socket limit under SecurityManager\n  - S7046823, CVE-2011-3544: missing SecurityManager checks in scripting engine\n  - S7055902, CVE-2011-3521: IIOP deserialization code execution\n  - S7057857, CVE-2011-3554: insufficient pack200 JAR files uncompress error checks\n  - S7064341, CVE-2011-3389: JSSE\n  - S7070134, CVE-2011-3558: Hotspot unspecified issue\n  - S7077466, CVE-2011-3556: RMI DGC server remote code execution\n  - S7083012, CVE-2011-3557: RMI registry privileged code execution\n  - S7096936, CVE-2011-3560: missing checkSetFactory calls in HttpsURLConnection\n NetX\n  - PR794: javaws does not work if a Web Start app jar has a Class-Path element in the manifest",
  "id": "ELSA-2011-1380",
  "ovalId": "oval:com.oracle.elsa:def:20111380",
  "source": "oracle_linux",
  "title": "ELSA-2011-1380:  java-1.6.0-openjdk security update (CRITICAL)",
  "url": "https://linux.oracle.com/errata/ELSA-2011-1380.html"
}