PT-2007-6315 · Sun+1 · Sun Java Runtime Environment+1

Published

2007-10-05

·

Updated

2018-10-30

·

CVE-2007-5232

CVSS v2.0

4.0

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Sun Java Runtime Environment (JRE) versions 6 Update 2 and earlier Sun Java Runtime Environment (JRE) versions 5.0 Update 12 and earlier Sun Java Runtime Environment (JRE) versions 1.4.2 15 and earlier Sun Java Runtime Environment (JRE) versions 1.3.1 20 and earlier
Description: The issue allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack when applet caching is enabled.
Recommendations: For versions 6 Update 2 and earlier, update to a version later than 6 Update 2 to resolve the issue. For versions 5.0 Update 12 and earlier, update to a version later than 5.0 Update 12 to resolve the issue. For versions 1.4.2 15 and earlier, update to a version later than 1.4.2 15 to resolve the issue. For versions 1.3.1 20 and earlier, update to a version later than 1.3.1 20 to resolve the issue. As a temporary workaround, consider disabling applet caching until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-5232
HPSBUX02284
RHSA-2007:0963
RHSA-2007:1041
RHSA-2008:0100
RHSA-2008:0132
RHSA-2008:0156

Affected Products

Hp-Ux
Sun Java Runtime Environment