Overview
The Sun Java Runtime Environment (JRE) contains a vulnerability that may allow unintended access to network resources.
Description
The Sun Java Runtime Environment (JRE) allows users to run Java applications in a browser or as standalone programs. Sun has made the JRE available for multiple operating systems. Per Sunsolve Document ID 103079: |
Impact
An attacker may be able to run a Java applet on a vulnerable system to gain access to network connections to resources not otherwise accessible and expose vulnerabilitites within those network resources. |
Solution
Upgrade |
Disable Java Disabling the Java browser plugin may prevent a malicious webpage from exploiting this vulnerability. See the Securing Your Web Browser for instructions on how to disable Java in your browser. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported in Sun Alert 103079. Sun credits Billy Rios of VeriSign with providing information about this issue.
This document was written by Joseph Pruszynski.
Other Information
CVE IDs: | CVE-2007-5232 |
Severity Metric: | 11.47 |
Date Public: | 2007-10-04 |
Date First Published: | 2007-10-05 |
Date Last Updated: | 2007-10-12 19:28 UTC |
Document Revision: | 14 |