PT-2010-2297 · Apple · Java For Macos X
Jeffrey Czerniak
+1
·
Published
2010-05-21
·
Updated
2010-05-24
·
CVE-2010-0539
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apple Java for Mac OS X versions 10.5 before Update 7
Apple Java for Mac OS X versions 10.6 before Update 2
Description
The issue is related to an integer signedness error in the window drawing implementation, which can be exploited by remote attackers. This can lead to the execution of arbitrary code or cause a denial of service, resulting in an application crash. The exploitation occurs via a crafted applet.
Recommendations
For Apple Java for Mac OS X versions 10.5 before Update 7, update to Update 7 or later to resolve the issue.
For Apple Java for Mac OS X versions 10.6 before Update 2, update to Update 2 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Java For Macos X