PT-2005-1528 · Sun · Sun Java Jre
Andreas Sandblad
·
Published
2005-02-19
·
Updated
2017-07-11
·
CVE-2005-0471
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Sun Java JRE versions 1.1.x through 1.4.x
Description
The issue allows remote attackers to write arbitrary files to known locations due to the predictable nature of temporary file names on file systems that use 8.3 style short names. This can facilitate the exploitation of vulnerabilities in applications that rely on unpredictable file names.
Recommendations
For Sun Java JRE versions 1.1.x through 1.4.x, consider restricting access to sensitive locations where temporary files are written until a patch is available. As a temporary workaround, avoid using file systems that utilize 8.3 style short names to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sun Java Jre