[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-2789Date: (C)2007-05-21   (M)2023-12-22


The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_19 and earlier, when running on Unix/Linux systems, allows remote attackers to cause a denial of service (JVM hang) via untrusted applets or applications that open arbitrary local files via a crafted BMP file, such as /dev/tty.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECTRACK-1018182
SUNALERT-102934
http://www.attrition.org/pipermail/vim/2007-July/001696.html
http://www.attrition.org/pipermail/vim/2007-July/001697.html
http://www.attrition.org/pipermail/vim/2007-July/001708.html
http://www.attrition.org/pipermail/vim/2007-December/001862.html
SUNALERT-200856
BID-24004
SECUNIA-25295
SECUNIA-25474
SECUNIA-25832
SECUNIA-26049
SECUNIA-26119
SECUNIA-26311
SECUNIA-26369
SECUNIA-26631
SECUNIA-26645
SECUNIA-26933
SECUNIA-27203
SECUNIA-27266
SECUNIA-28056
SECUNIA-28115
SECUNIA-29340
SECUNIA-29858
SECUNIA-30780
SECUNIA-30805
ADV-2007-1836
ADV-2007-3009
ADV-2007-4224
APPLE-SA-2007-12-14
BEA07-177.00
GLSA-200705-23
GLSA-200706-08
GLSA-200709-15
GLSA-200804-20
GLSA-200804-28
GLSA-200806-11
RHSA-2007:0817
RHSA-2007:0829
RHSA-2007:0956
RHSA-2007:1086
RHSA-2008:0100
RHSA-2008:0133
RHSA-2008:0261
SUSE-SA:2007:045
SUSE-SA:2007:056
http://docs.info.apple.com/article.html?artnum=307177
http://scary.beasts.org/security/CESA-2006-004.html
http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html
http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html
oval:org.mitre.oval:def:10800
sun-java-virtual-machine-dos(34654)
sunjava-bmp-dos(34320)

CPE    88
cpe:/a:sun:jdk:1.5.0:update10
cpe:/a:sun:sdk:1.3.1_19
cpe:/a:sun:sdk:1.3.1_17
cpe:/a:sun:sdk:1.3.1_18
...
CWE    1
CWE-399

© SecPod Technologies