---
title: "CVE-2012-0500\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-0500?format=md
keywords: index, follow
---

# CVE-2012-0500

Publication date 15 February 2012

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component
in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and
JavaFX 2.0.2 and earlier allows remote untrusted Java Web Start
applications and untrusted Java applets to affect confidentiality,
integrity, and availability via unknown vectors related to Deployment.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2012-0500?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| icedtea-web | 13.04 raring | Not affected |
| 12.10 quantal | Not affected |
| 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.10 maverick | Not in release |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not in release |
| openjdk-6 | 13.04 raring | Not affected |
| 12.10 quantal | Not affected |
| 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not affected |
| openjdk-6b18 | 13.04 raring | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not in release |
| openjdk-7 | 13.04 raring | Not affected |
| 12.10 quantal | Not affected |
| 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not affected |
| 11.04 natty | Not in release |
| 10.10 maverick | Not in release |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |
| sun-java5 | 13.04 raring | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 11.04 natty | Not in release |
| 10.10 maverick | Not in release |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Ignored end of life |
| sun-java6 | 13.04 raring | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 11.04 natty | Not in release |
| 10.10 maverick | Not in release |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

in natty+, NetX and the plugin moved to the icedtea-web package

---

### [sbeattie](https://launchpad.net/~sbeattie)

not referenced in upstream icedtea 6 notes, assuming it affects
sun-java6 only

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0500)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-0500)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-0500)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-0500)

### Other references

* <http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html#AppendixJAVA>
* <http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-February/017249.html>
* <https://www.cve.org/CVERecord?id=CVE-2012-0500>
