PT-2010-4920 · Oracle+2 · Java Se+4
Published
2010-10-12
·
Updated
2018-10-30
·
CVE-2010-3559
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Java SE and Java for Business versions 6 Update 21 through 6 Update 21
Oracle Java SE and Java for Business version 5.0 Update 25
Oracle Java SE and Java for Business version 1.4.2 27
Oracle Java SE and Java for Business version 1.3.1 28
Description
The issue affects the Sound component, potentially allowing remote attackers to impact confidentiality, integrity, and availability. It is claimed by a researcher that this could involve an incorrect sign extension in the
HeadspaceSoundbank.nGetName function, possibly leading to arbitrary code execution via a crafted BANK record that causes a buffer overflow.Recommendations
For Oracle Java SE and Java for Business version 6 Update 21, update to a version that includes the fix for this issue.
For Oracle Java SE and Java for Business version 5.0 Update 25, update to a version that includes the fix for this issue.
For Oracle Java SE and Java for Business version 1.4.2 27, update to a version that includes the fix for this issue.
For Oracle Java SE and Java for Business version 1.3.1 28, update to a version that includes the fix for this issue.
As a temporary workaround, consider disabling the
HeadspaceSoundbank.nGetName function until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp-Ux
Java Platform
Java Se
Java For Business
Red Hat