Overview
The Sun Java Runtime Environment contains a buffer overflow vulnerability that may allow an attacker to execute code or read local files.
Description
The Java Runtime Environment (JRE) is a group software packages from Sun Microsystems that allow a computer to access and use Java applications. Sun distributes a JRE plug-in for web browsers that allow websites to include Java applications that can execute in the user's web browser. The JRE is part of the Java Development Kit (JDK). The International Color Consortium (ICC) supports cross-platform color management systems. One of these systems is the ICC profile format. |
Impact
A remote, unauthenticated attacker may be able to read or write files and execute code with the privileges of the user who is running the JRE. |
Solution
|
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.sunsolve.sun.com/search/document.do?assetkey=1-26-102934-1
- http://java.sun.com/j2se/1.5.0/docs/guide/deployment/deployment-guide/jcp.html#update
- http://scary.beasts.org/security/CESA-2006-004.html
- http://java.sun.com/j2se/1.4.2/download.html
- http://java.com/en/download/help/testvm.xml
- http://www.cert.org/tech_tips/securing_browser/
- http://www.color.org/
- http://www.auscert.org.au/render.html?it=7664&template=1
- http://www.securityfocus.com/bid/24004
- http://xforce.iss.net/xforce/xfdb/34318
Acknowledgements
Thanks to Sun for information that was used in this report. Sun thanks Chris Evans for reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2007-2788 |
Severity Metric: | 12.39 |
Date Public: | 2007-06-04 |
Date First Published: | 2007-06-06 |
Date Last Updated: | 2007-07-16 22:21 UTC |
Document Revision: | 22 |