PT-2010-4920 · Oracle+2 · Java Se+4
Publicado
2010-10-12
·
Atualizado
2018-10-30
·
CVE-2010-3559
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Java SE and Java for Business versions 6 Update 21 through 6 Update 21
Oracle Java SE and Java for Business version 5.0 Update 25
Oracle Java SE and Java for Business version 1.4.2 27
Oracle Java SE and Java for Business version 1.3.1 28
Description
The issue affects the Sound component, potentially allowing remote attackers to impact confidentiality, integrity, and availability. It is claimed by a researcher that this could involve an incorrect sign extension in the
HeadspaceSoundbank.nGetName function, possibly leading to arbitrary code execution via a crafted BANK record that causes a buffer overflow.Recommendations
For Oracle Java SE and Java for Business version 6 Update 21, update to a version that includes the fix for this issue.
For Oracle Java SE and Java for Business version 5.0 Update 25, update to a version that includes the fix for this issue.
For Oracle Java SE and Java for Business version 1.4.2 27, update to a version that includes the fix for this issue.
For Oracle Java SE and Java for Business version 1.3.1 28, update to a version that includes the fix for this issue.
As a temporary workaround, consider disabling the
HeadspaceSoundbank.nGetName function until a patch is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hp-Ux
Java Platform
Java Se
Java For Business
Red Hat