There's a typo in the CVE number. It's: CVE-2012-0158
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0...
...and how is this not a Windows vulnerability, and instead Java?
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0...
...and how is this not a Windows vulnerability, and instead Java?
So it is a Java issue only in the sense that Oracle needs to update it. Obviously the original "bad code" was from Microsoft.
[0] https://technet.microsoft.com/en-us/library/security/ms12-02... [1] https://community.emc.com/community/connect/rsaxchange/netwi...
The closest thing to that is this, Securia PSI: