CVE-2012-0507
sun jre, oracle jre, debian linux
Published 7 Jun 2012 · updated 14 Aug 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Mar 2022, with a remediation deadline of 24 Mar 2022 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply updates per vendor instructions.
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.
References
- blogs.technet.com/b/mmpc/archive/2012/03/20/an-interesting-case-of-jre-sandbox-breach-cve-2012-0507.aspx · Broken Link, Third Party Advisory
- krebsonsecurity.com/2012/03/new-java-attack-rolled-into-exploit-packs/ · Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html · Issue Tracking, Third Party Advisory
- lists.opensuse.org/opensuse-security-announce/2012-05/msg00010.html · Mailing List, Third Party Advisory
- marc.info/?l=bugtraq&m=133364885411663&w=2 · Third Party Advisory
- marc.info/?l=bugtraq&m=133365109612558&w=2 · Third Party Advisory
- marc.info/?l=bugtraq&m=133847939902305&w=2 · Third Party Advisory
- marc.info/?l=bugtraq&m=134254866602253&w=2 · Third Party Advisory
- marc.info/?l=bugtraq&m=134254957702612&w=2 · Third Party Advisory
- rhn.redhat.com/errata/RHSA-2012-0508.html · Third Party Advisory
- rhn.redhat.com/errata/RHSA-2012-0514.html · Third Party Advisory
- rhn.redhat.com/errata/RHSA-2013-1455.html · Third Party Advisory
- secunia.com/advisories/48589 · Broken Link, Not Applicable
- secunia.com/advisories/48692 · Broken Link, Not Applicable
- secunia.com/advisories/48915 · Broken Link, Not Applicable
- secunia.com/advisories/48948 · Broken Link, Not Applicable
- secunia.com/advisories/48950 · Broken Link, Not Applicable
- weblog.ikvm.net/PermaLink.aspx?guid=cd48169a-9405-4f63-9087-798c4a1866d3 · Broken Link, Exploit
- www.debian.org/security/2012/dsa-2420 · Mailing List, Third Party Advisory
- www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html · Vendor Advisory
- www.securityfocus.com/bid/52161 · Broken Link, Exploit, Third Party Advisory
- bugzilla.redhat.com/show_bug.cgi?id=788994 · Issue Tracking
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0507 · US Government Resource