---
title: "CVE-2010-3568\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2010-3568?format=md
keywords: index, follow
---

# CVE-2010-3568

Publication date 19 October 2010

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Unspecified vulnerability in the Java Runtime Environment component in
Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and
1.4.2\_27 allows remote attackers to affect confidentiality, integrity, and
availability via unknown vectors. NOTE: the previous information was
obtained from the October 2010 CPU. Oracle has not commented on claims
from a reliable downstream vendor that this is a race condition related to
deserialization.

### From the Ubuntu Security Team

It was discovered that an unspecified race condition in the way
objects were deserialized could allow an attacker to cause an applet
or application to misuse the privileges of the user running the
java applet or application.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2010-3568?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openjdk-6 | 10.10 maverick | Fixed 6b20-1.9.1-1ubuntu3 |
| 10.04 LTS lucid | Fixed 1.8.2-4ubuntu2 |
| 9.10 karmic | Fixed 1.8.2-4ubuntu1~9.10.1 |
| 9.04 jaunty | Fixed 1.8.2-4ubuntu1~9.04.1 |
| 8.04 LTS hardy | Fixed 1.8.2-4ubuntu1~8.04.1 |
| 6.06 LTS dapper | Not in release |
| openjdk-6b18 | 10.10 maverick | Fixed 6b18-1.8.2-4ubuntu1 |
| 10.04 LTS lucid | Not affected |
| 9.10 karmic | Not affected |
| 8.10 intrepid | Not in release |
| 8.04 LTS hardy | Not in release |
| 6.06 LTS dapper | Not in release |
| sun-java6 | 10.10 maverick | Fixed 6.22-0ubuntu1~10.10 |
| 10.04 LTS lucid | Fixed 6.22-0ubuntu1~10.04 |
| 9.10 karmic | Fixed 6.22-0ubuntu1~9.10.1 |
| 9.04 jaunty | Fixed 6.22-0ubuntu1~9.04.1 |
| 8.04 LTS hardy | Fixed 6.22-0ubuntu1~8.04.1 |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

red hat description: Race condition in the way objects
were deserialized could allow an untrusted applet or application to
misuse the privileges of the user running the applet or application.

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3568)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2010-3568)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2010-3568)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2010-3568)

### Related Ubuntu Security Notices (USN)

+ [USN-1010-1](https://usn.ubuntu.com/USN-1010-1)
+ OpenJDK vulnerabilities
+ 28 October 2010

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2010-3568>
