Ubuntu Security Notice 859-1: OpenJDK Vulnerabilities

November 13, 2009, 10:35 am

Dan Kaminsky discovered that SSL certificates signed with MD2 could be spoofed given enough time. As a result, an attacker could potentially create a malicious trusted certificate to impersonate another site. This update handles this issue by completely disabling MD2 for certificate validation in OpenJDK. (CVE-2009-2409)

It was discovered that ICC profiles could be identified with “..” pathnames. If a user were tricked into running a specially crafted applet, a remote attacker could gain information about a local system. (CVE-2009-3728)…

