PT-2003-2108 · Oracle+1 · Software Development Kit+2
Published
2003-12-31
·
Updated
2017-07-11
·
CVE-2003-1156
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Java Runtime Environment (JRE) and Software Development Kit (SDK) versions 1.4.2 through 1.4.2 02
Description
The issue allows local users to overwrite arbitrary files via a symlink attack on certain files created by the unpack program or the RPM program.
Recommendations
For Java Runtime Environment (JRE) and Software Development Kit (SDK) versions 1.4.2 through 1.4.2 02, consider updating to a version outside of this range to mitigate the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Java Runtime Environment
Rpm
Software Development Kit