PT-2004-3432 · Oracle · Software Development Kit+2

Publicado

2004-12-31

·

Atualizado

2017-07-11

·

CVE-2004-2540

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Java Runtime Environment (JRE) versions 1.4.0 through 1.4.2 05 Software Development Kit (SDK) versions 1.4.0 through 1.4.2 05
Description The issue allows remote attackers to cause a denial of service, making the Java Virtual Machine (JVM) unresponsive, via crafted serialized data. This is due to the readObject method in the affected Java Runtime Environment (JRE) and Software Development Kit (SDK) versions.
Recommendations For Java Runtime Environment (JRE) versions 1.4.0 through 1.4.2 05, consider updating to a version that contains a fix for this issue. For Software Development Kit (SDK) versions 1.4.0 through 1.4.2 05, consider updating to a version that contains a fix for this issue. As a temporary workaround, consider restricting the use of the readObject method until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-2540

Produtos afetados

Java Runtime Environment
Java Virtual Machine
Software Development Kit