A buffer overflow vulnerability exists in Cosminexus, Processing Kit for XML, and Hitachi Developer's Kit for Java, when Java applications process image files.
Vulnerability description
A buffer overflow vulnerability exists in Cosminexus, Processing Kit for XML, and Hitachi Developer's Kit for Java, which are component products of the following:
- Cosminexus V8, V7, V6.7
- uCosminexus Application Server Enterprise
- uCosminexus Application Server Standard
- uCosminexus Service Platform
- uCosminexus Developer Standard
- uCosminexus Developer Professional
- uCosminexus Developer Light
- uCosminexus Service Architect
- uCosminexus Operator
- uCosminexus Client
- Cosminexus V6
- Cosminexus Application Server Enterprise Version 6
- Cosminexus Application Server Standard Version 6
- Cosminexus Developer Standard Version 6
- Cosminexus Developer Professional Version 6
- Cosminexus Developer Light Version 6
- Cosminexus Client Version 6
- Cosminexus V5
- Cosminexus Application Server Version 5
- Cosminexus Developer Version 5
- Cosminexus Studio Version 5
- Cosminexus V4
- Cosminexus Studio - Web Edition Version 4(*1)
- Cosminexus Server - Web Edition Version 4(*1)
- Cosminexus Studio - Standard Edition Version 4(*1)
- Cosminexus Server - Standard Edition Version 4(*1)
- Products containing Cosminexus
- uCosminexus Navigation Platform(*2)
- uCosminexus Navigation Platform - User License(*2)
- uCosminexus Navigation Platform - Authoring License(*2)
- uCosminexus Navigation Developer(*2)
- Electronic Form Workflow Set(*2)
- Electronic Form Workflow - Professional Set(*2)
- Electronic Form Workflow - Developer Set(*2)
- Electronic Form Workflow - Standard Set(*2)
- Electronic Form Workflow - Professional Library Set(*2)
- Electronic Form Workflow - Developer Client Set(*2)
- uCosminexus Collaboration - Server(*2)
- Groupmax Collaboration - Server(*2)
- uCosminexus/OpenTP1 Web Front-end Set(*2)
- Cosminexus/OpenTP1 Web Front-end Set(*2)
- uCosminexus Portal Framework Entry Set(*3)
- Non-Cosminexus Products
- Processing Kit for XML
- IBM XL C/C++ Enterprise Edition V7 for AIX & Hitachi Developer's Kit for Java(TM)(*4)
- IBM XL C/C++ Enterprise Edition V8 for AIX & Hitachi Developer's Kit for Java(TM)(*4)
- *1
- Java Runtime Environment contained in these products is affected.
- *2
- uCosminexus Application Server Standard and uCosminexus Developer Standard contained in these products are affected.
- *3
- uCosminexus Application Server Standard contained in these products is affected.
- *4
- Hitachi Developer's Kit for Java(TM) contained in these products is affected.
Affected products
The information is organized under the following headings:
(Example)
Product name: Gives the name of the affected product.
Version:
- Platform
- Gives the affected version.
- Cosminexus V8
Product name: uCosminexus Application Server Enterprise
Product name: uCosminexus Application Server Standard
Version(s):
- Windows
- 08-00
- Linux
- 08-00 to 08-20
- Linux(IPF)
- 08-00
- AIX
- 08-00
- HP-UX(IPF)
- 08-00
- Solaris(SPARC)
- 08-00
- Solaris(x64)
- 08-20
Product name: uCosminexus Service Platform
Version(s):
- Windows
- 08-00 to 08-10
- Linux
- 08-00 to 08-10
- Linux(IPF)
- 08-00 to 08-10
- AIX
- 08-00 to 08-10
- HP-UX(IPF)
- 08-00 to 08-10
Product name: uCosminexus Service Architect
Version(s):
- Windows
- 08-00 to 08-10
Product name: uCosminexus Developer Standard
Product name: uCosminexus Developer Professional
Product name: uCosminexus Client
Version(s):
- Windows
- 08-00
- Cosminexus V7
Product name: uCosminexus Application Server Enterprise
Product name: uCosminexus Application Server Standard
Version(s):
- Windows
- 07-00 to 07-60
- Linux
- 07-00 to 07-60
- Linux(IPF)
- 07-10 to 07-60
- AIX
- 07-00 to 07-60
- HP-UX
- 07-10
- HP-UX(IPF)
- 07-00 to 07-60
- Solaris
- 07-00 to 07-60
Product name: uCosminexus Service Platform
Version(s):
- Windows
- 07-00 to 07-60
- Linux
- 07-00 to 07-60
- AIX
- 07-10 to 07-60
Product name: uCosminexus Developer Standard
Product name: uCosminexus Developer Professional
Product name: uCosminexus Service Architect
Product name: uCosminexus Operator
Product name: uCosminexus Client
Version(s):
- Windows
- 07-00 to 07-60
- Cosminexus V6.7
Product name: uCosminexus Application Server Enterprise
Product name: uCosminexus Application Server Standard
Version(s):
- Windows
- 06-70 to 06-70-/F(*6), 06-71 to 06-71-/G
- Windows(IPF)
- 06-70 to 06-70-/A(*6)
- Linux
- 06-70 to 06-70-/F(*6), 06-71 to 06-71-/H(*6)
- Linux(IPF)
- 06-70 to 06-70-/G(*6)
- AIX
- 06-70 to 06-70-/N
- HP-UX
- 06-70 to 06-70-/E(*6), 06-72 to 06-72-/D(*6)
- HP-UX(IPF)
- 06-70 to 06-70-/N(*6)
- Solaris
- 06-70 to 06-70-/E(*6)
Product name: uCosminexus Developer Standard
Product name: uCosminexus Developer Professional
Product name: uCosminexus Developer Light
Product name: uCosminexus Client
Version(s):
- Windows
- 06-70 to 06-70-/F(*6), 06-71 to 06-71-/G
- Cosminexus V6
Product name: Cosminexus Application Server Enterprise Version 6(*5)
Product name: Cosminexus Application Server Standard Version 6(*5)
Version(s):
- Windows
- 06-00 to 06-00-/I, 06-02 to 06-02-/G, 06-50 to 06-50-/F, 06-51 to 06-51-/L
- Linux
- 06-00 to 06-00-/E, 06-02 to 06-02-/F, 06-50 to 06-50-/C, 06-51 to 06-51-/E
- Linux(IPF)
- 06-00 to 06-00-/B, 06-02 to 06-02-/D, 06-50 to 06-50-/B, 06-51 to 06-51-/B
- AIX
- 06-00 to 06-00-/I, 06-50 to 06-50-/I
- HP-UX
- 06-00 to 06-00-/E, 06-50 to 06-50-/F
- HP-UX(IPF)
- 06-00 to 06-00-/E, 06-50 to 06-50-/E
- Solaris
- 06-50 to 06-50-/C
Product name: Cosminexus Developer Standard Version 6(*5)
Product name: Cosminexus Developer Professional Version 6(*5)
Product name: Cosminexus Developer Light Version 6(*5)
Product name: Cosminexus Client Version 6(*5)
Version(s):
- Windows
- 06-00 to 06-00-/I, 06-02 to 06-02-/G, 06-50 to 06-50-/F, 06-51 to 06-51-/L
- Cosminexus V5
Product name: Cosminexus Application Server Version 5(*5)
Version(s):
- Windows
- 05-00 to 05-00-/I, 05-01 to 05-01-/L, 05-05 to 05-05-/P
- Linux
- 05-05 to 05-05-/I
- AIX
- 05-00 to 05-00-/S, 05-05 to 05-05-/O
- HP-UX
- 05-02 to 05-02-/E, 05-05 to 05-05-/I
Product name: Cosminexus Developer Version 5(*5)
Product name: Cosminexus Studio Version 5(*5)
Version(s):
- Windows
- 05-00 to 05-00-/I, 05-01 to 05-01-/L, 05-05 to 05-05-/P
- Cosminexus V4
Product name: Cosminexus Studio - Web Edition Version 4(*5)
Product name: Cosminexus Server - Web Edition Version 4(*5)
Product name: Cosminexus Studio - Standard Edition Version 4(*5)
Product name: Cosminexus Server - Standard Edition Version 4(*5)
Version(s):
- Windows
- 04-00 to 04-00-/A, 04-01 to 04-01-/A
- Products containing Cosminexus
Product name: uCosminexus Navigation Platform
Product name: uCosminexus Navigation Platform - User License
Product name: uCosminexus Navigation Platform - Authoring License
Product name: uCosminexus Navigation Developer
Version(s):
- Windows
- 08-00, 08-01, 08-10 to 08-10-/A
Product name: Electronic Form Workflow Set
Product name: Electronic Form Workflow - Developer Set
Version(s):
- Windows
- 07-50 to 07-50-/D, 07-60 to 07-60-/I
Product name: Electronic Form Workflow - Professional Set
Version(s):
- Windows
- 07-50 to 07-50-/D
Product name: Electronic Form Workflow - Standard Set
Version(s):
- Windows
- 06-70 to 06-70-/F(*6), 07-00 to 07-00-/C, 07-10 to 07-10-/A, 07-11 to 07-11-/C, 07-20 to 07-20-/B
- Linux
- 06-70 to 06-70-/C(*6), 07-00 to 07-00-/B, 07-10 to 07-10-/A, 07-20
Product name: Electronic Form Workflow - Professional Library Set
Version(s):
- Windows
- 06-70 to 06-70-/F(*6), 07-00 to 07-00-/C, 07-10 to 07-10-/A, 07-11 to 07-11-/C, 07-20 to 07-20-/B
- Linux
- 06-70 to 06-70-/C(*6), 07-00 to 07-00-/B, 07-10 to 07-10-/A
Product name: Electronic Form Workflow - Developer Client Set
Version(s):
- Windows
- 06-70 to 06-70-/F(*6), 07-00 to 07-00-/C, 07-10 to 07-10-/A, 07-11 to 07-11-/C, 07-20 to 07-20-/B
Product name: uCosminexus Collaboration - Server(*5)
Version(s):
- Windows
- 06-20 to 06-20-/D, 06-30 to 06-30-/F, 06-35 to 06-35-/H
Product name: Groupmax Collaboration - Server(*5)
Version(s):
- Windows
- 07-20 to 07-20-/D, 07-30 to 07-30-/F, 07-35 to 07-35-/H
Product name: uCosminexus/OpenTP1 Web Front-end Set(*5)
Version(s):
- Windows
- 02-70 to 02-70-/A
Product name: Cosminexus/OpenTP1 Web Front-end Set(*5)
Version(s):
- Windows
- 01-00 to 01-00-/B, 01-01 to 01-01-/C, 02-00 to 02-00-/A, 02-50 to 02-50-/A
- Non-Cosminexus Products
Product name: Processing Kit for XML(*5)
Version(s):
- Windows
- 01-05 to 01-05-/C, 02-00 to 02-00-/C
- Windows(English version)
- 01-05 to 01-05-/B
- Linux
- 01-05 to 01-05-/A, 02-00, 02-05 to 02-05-/A
- Linux(IPF)
- 02-00 to 02-00-/B, 02-05 to 02-05-/A
- AIX
- 01-00, 01-05 to 01-05-/C, 02-00 to 02-00-/D
- HP-UX
- 01-05 to 01-05-/D, 01-07 to 01-07-/A
- HP-UX(IPF)
- 02-05 to 02-05-/C
- Solaris
- 02-05 to 02-05-/A
Product name: IBM XL C/C++ Enterprise Edition V7 for AIX & Hitachi Developer's Kit for Java(TM)
Product name: IBM XL C/C++ Enterprise Edition V8 for AIX & Hitachi Developer's Kit for Java(TM)
Version(s):
- AIX
- 01-00
- *5
- For details about these products, contact your Hitachi support service representative.
- *6
- For details about these versions, contact your Hitachi support service representative.
Fixed products
The information is organized under the following headings:
(Example)
Product name: Gives the name of the fixed product.
Version:
- Platform
- Gives the fixed version, and release date.
Scheduled version(s):
- Platform
- Gives the fixed version scheduled to be released.
- Cosminexus V8
Product name: uCosminexus Application Server Enterprise
Product name: uCosminexus Application Server Standard
Product name: uCosminexus Service Platform
Product name: uCosminexus Developer Standard
Product name: uCosminexus Developer Professional
Product name: uCosminexus Service Architect
Product name: uCosminexus Client
Fixed component product name(*8):
- Cosminexus Developer's Kit for Java(TM)
Fixed component product version(s)(*8):
- Windows
- 08-00-03 November 11, 2009
- Linux
- 08-00-02 December 3, 2009
- Linux(x64)
- 08-00-02 December 3, 2009
- Linux(IPF)
- 08-00-02 May 17, 2010
- AIX
- 08-00-03 May 19, 2010
- HP-UX(IPF)
- 08-00-02 December 17, 2009
- Solaris(SPARC)
- 08-00-02 March 16, 2010
- Cosminexus V7
Product name: uCosminexus Application Server Enterprise
Product name: uCosminexus Application Server Standard
Product name: uCosminexus Service Platform
Product name: uCosminexus Developer Standard
Product name: uCosminexus Developer Professional
Product name: uCosminexus Service Architect
Product name: uCosminexus Operator
Product name: uCosminexus Client
Fixed component product name(*8):
- Cosminexus Developer's Kit for Java(TM)
Fixed component product version(s)(*8):
- Windows
- 07-00-11 December 25, 2009
- 07-50-11 November 26, 2009
- Linux
- 07-00-11 February 10, 2010
- Linux(x64)
- 07-00-07 February 10, 2010
- Linux(IPF)
- 07-00-07 April 23, 2010
- 07-03-04 April 23, 2010
- AIX
- 07-00-11 March 8, 2010
- HP-UX
- 07-00-07 September 1, 2010
- HP-UX(IPF)
- 07-00-07 June 16, 2010
- 07-03-03 June 16, 2010
- Solaris
- 07-00-07 April 26, 2010
- 07-03-03 April 26, 2010
- Cosminexus V6.7
Product name: uCosminexus Application Server Enterprise
Product name: uCosminexus Application Server Standard
Product name: uCosminexus Developer Standard
Product name: uCosminexus Developer Professional
Product name: uCosminexus Developer Light
Product name: uCosminexus Client
Version(s)(*7):
- Windows
- 06-71-/H February 5, 2010
- AIX
- 06-70-/O December 14, 2009
- Products containing Cosminexus
Product name: uCosminexus Navigation Platform
Product name: uCosminexus Navigation Platform - User License
Product name: uCosminexus Navigation Platform - Authoring License
Product name: uCosminexus Navigation Developer
Version(s)(*7):
- Windows
- 08-21-/A December 22, 2010
Product name: Electronic Form Workflow Set
Product name: Electronic Form Workflow - Professional Set
Product name: Electronic Form Workflow - Developer Set
Fixed component product name:
- Cosminexus Developer's Kit for Java(TM)
Fixed component product version(s)(*8):
- Windows
- 07-50-11 November 26, 2009
Product name: Electronic Form Workflow - Standard Set
Product name: Electronic Form Workflow - Professional Library Set
Fixed component product name:
- Cosminexus Developer's Kit for Java(TM)
Fixed component product version(s)(*8):
- Windows
- 07-00-11 December 25, 2009
- Linux
- 07-00-11 February 10, 2010
Product name: Electronic Form Workflow - Developer Client Set
Fixed component product name:
- Cosminexus Developer's Kit for Java(TM)
Fixed component product version(s)(*8):
- Windows
- 07-00-11 December 25, 2009
- Non-Cosminexus Products
Product name: IBM XL C/C++ Enterprise Edition V7 for AIX & Hitachi Developer's Kit for Java(TM)
Product name: IBM XL C/C++ Enterprise Edition V8 for AIX & Hitachi Developer's Kit for Java(TM)
Fixed component product name(*9):
- Hitachi Developer's Kit for Java(TM)
Fixed component product version(s)(*9):
- AIX
- 02-05-/R December 10, 2009
For details on the fixed products, contact your Hitachi support service representative.
- *7
- Before applying the fixed version, it might be necessary to upgrade to a more recent revision or product.
- *8
- Cosminexus Developer's Kit for Java(TM), which is a component product, has been fixed. Apply the fixed version of the component product.
- *9
- Hitachi Developer's Kit for Java(TM), which is a component product, is fixed. Apply the fixed version of the component product.