PT-2003-2108 · Oracle+1 · Software Development Kit+2
Publicado
2003-12-31
·
Atualizado
2017-07-11
·
CVE-2003-1156
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Java Runtime Environment (JRE) and Software Development Kit (SDK) versions 1.4.2 through 1.4.2 02
Description
The issue allows local users to overwrite arbitrary files via a symlink attack on certain files created by the unpack program or the RPM program.
Recommendations
For Java Runtime Environment (JRE) and Software Development Kit (SDK) versions 1.4.2 through 1.4.2 02, consider updating to a version outside of this range to mitigate the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Java Runtime Environment
Rpm
Software Development Kit