PT-2010-2566 · Oracle+1 · Java Se+3

Peter Vreugdenhil

·

Published

2010-04-01

·

Updated

2018-10-10

·

CVE-2010-0843

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Java SE and Java for Business versions 6 Update 18, 5.0 Update 23, 1.4.2 25, and 1.3.1 27
Description The issue affects the Sound component, allowing remote attackers to impact confidentiality, integrity, and availability through unknown vectors. It is reportedly related to improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, potentially enabling remote attackers to execute arbitrary code.
Recommendations For Oracle Java SE and Java for Business version 6 Update 18, update to a version that includes the fix for this issue. For Oracle Java SE and Java for Business version 5.0 Update 23, update to a version that includes the fix for this issue. For Oracle Java SE and Java for Business version 1.4.2 25, update to a version that includes the fix for this issue. For Oracle Java SE and Java for Business version 1.3.1 27, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Sound component until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-0843
HPSBUX02524
RHSA-2010:0337
RHSA-2010:0338
RHSA-2010:0383
RHSA-2010:0471
RHSA-2010:0489
RHSA-2010:0574
RHSA-2010:0586
ZDI-10-052

Affected Products

Hp-Ux
Java Platform
Java Se
Java For Business