PT-2010-2566 · Oracle+1 · Java Se+3
Peter Vreugdenhil
·
Published
2010-04-01
·
Updated
2018-10-10
·
CVE-2010-0843
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Java SE and Java for Business versions 6 Update 18, 5.0 Update 23, 1.4.2 25, and 1.3.1 27
Description
The issue affects the Sound component, allowing remote attackers to impact confidentiality, integrity, and availability through unknown vectors. It is reportedly related to improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, potentially enabling remote attackers to execute arbitrary code.
Recommendations
For Oracle Java SE and Java for Business version 6 Update 18, update to a version that includes the fix for this issue.
For Oracle Java SE and Java for Business version 5.0 Update 23, update to a version that includes the fix for this issue.
For Oracle Java SE and Java for Business version 1.4.2 25, update to a version that includes the fix for this issue.
For Oracle Java SE and Java for Business version 1.3.1 27, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the Sound component until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp-Ux
Java Platform
Java Se
Java For Business