PT-2007-6125 · Oracle · Java Web Start+1

Yag Kohha

·

Published

2007-09-20

·

Updated

2017-09-29

·

CVE-2007-5019

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Java Runtime Environment (JRE) version 1.6.0 X
Description The issue is related to a buffer overflow in the Sun Java Web Start ActiveX control. This occurs when a long argument is passed to the dnsResolve method, potentially allowing remote attackers to have an unknown impact.
Recommendations For Java Runtime Environment (JRE) version 1.6.0 X, consider restricting access to the dnsResolve method as a temporary workaround until a patch is available.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5019

Affected Products

Java Runtime Environment
Java Web Start