The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Java | — | Upgrade to Apple Java version 1.5.0.28Upgrade to Apple Java version 1.6.0.24 | Jan 26, 2012 | Feb 17, 2011 |
| Centos_linux | — | Upgrade tomcat5-common-libUpgrade tomcat5-server-libUpgrade tomcat5-webappsUpgrade tomcat5-admin-webappsUpgrade tomcat5-jasperUpgrade tomcat5-jasper-javadocUpgrade tomcat5Upgrade tomcat5-servlet-2.4-apiUpgrade java-1.6.0-openjdk-javadocUpgrade java-1.6.0-openjdkUpgrade tomcat5-jsp-2.0-apiUpgrade tomcat5-jsp-2.0-api-javadocUpgrade java-1.6.0-openjdk-srcUpgrade java-1.6.0-openjdk-demoUpgrade tomcat5-servlet-2.4-api-javadocUpgrade java-1.6.0-openjdk-devel | Dec 1, 2016 | Feb 17, 2011 |
| Gentoo Linux | — | Upgrade app-emulation/emul-linux-x86-java.Upgrade dev-java/icedtea-bin.Upgrade dev-java/sun-jdk.Upgrade dev-java/sun-jre-bin. | Oct 30, 2017 | Feb 17, 2011 |
| Hpsim | — | Upgrade to the latest version of HP Systems Insight Manager | Oct 13, 2015 | Feb 17, 2011 |
| Hpux | — | Update Jre60.JRE60-IPF64 to the latest versionUpdate Jdk15.JDK15-COM to the latest versionUpdate Jdk60.JDK60-IPF32 to the latest versionUpdate hpuxwsAPCH32.APACHE to the latest versionUpdate hpuxwsAPACHE.APACHE2 to the latest versionUpdate Jre60.JRE60-IPF64-HS to the latest versionUpdate hpuxwsAPCH32.MOD_JK to the latest versionUpdate hpuxwsAPACHE.WEBPROXY to the latest versionUpdate hpuxwsAPACHE.PHP2 to the latest versionUpdate hpuxwsAPACHE.PHP to the latest versionUpdate Jre60.JRE60-PA20 to the latest versionUpdate hpuxws22TOMCAT.TOMCAT to the latest versionUpdate hpuxwsAPACHE.MOD_JK to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP2 to the latest versionUpdate Jdk60.JDK60-IPF64 to the latest versionUpdate hpuxwsAPACHE.MOD_PERL to the latest versionUpdate Jdk15.JDK15-PA20 to the latest versionUpdate Jre60.JRE60-PA20-HS to the latest versionUpdate Jre15.JRE15-IPF64 to the latest versionUpdate Jre15.JRE15-PA20 to the latest versionUpdate Jre15.JRE15-PA20W-HS to the latest versionUpdate Jdk15.JDK15-IPF32 to the latest versionUpdate Jre15.JRE15-IPF64-HS to the latest versionUpdate Jre60.JRE60-COM to the latest versionUpdate Jre15.JRE15-COM to the latest versionUpdate Jdk60.JDK60-PA20 to the latest versionUpdate Jre60.JRE60-IPF32 to the latest versionUpdate hpuxwsAPCH32.AUTH_LDAP2 to the latest versionUpdate hpuxwsAPCH32.MOD_JK2 to the latest versionUpdate Jre15.JRE15-IPF32 to the latest versionUpdate Jre15.JRE15-IPF32-HS to the latest versionUpdate Jdk60.JDK60-COM to the latest versionUpdate Jre15.JRE15-PA20W to the latest versionUpdate hpuxwsAPCH32.PHP2 to the latest versionUpdate hpuxwsAPCH32.AUTH_LDAP to the latest versionUpdate hpuxwsAPCH32.APACHE2 to the latest versionUpdate hpuxwsAPACHE.APACHE to the latest versionUpdate hpuxwsAPCH32.MOD_PERL2 to the latest versionUpdate hpuxwsAPCH32.WEBPROXY to the latest versionUpdate Jre60.JRE60-IPF32-HS to the latest versionUpdate hpuxwsAPCH32.MOD_PERL to the latest versionUpdate Jdk60.JDK60-PA20W to the latest versionUpdate hpuxwsAPACHE.MOD_PERL2 to the latest versionUpdate Jdk15.JDK15-PA20W to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP to the latest versionUpdate Jre15.JRE15-PA20-HS to the latest versionUpdate hpuxwsAPACHE.MOD_JK2 to the latest versionUpdate Jre60.JRE60-PA20W-HS to the latest versionUpdate hpuxwsAPCH32.PHP to the latest versionUpdate Jdk15.JDK15-IPF64 to the latest version | Aug 11, 2017 | Feb 17, 2011 |
| Jre Vuln | — | Upgrade to the latest version of Oracle Java | Feb 17, 2011 | Feb 17, 2011 |
| Oracle_linux | — | Upgrade java-1.6.0-openjdkUpgrade java-1.6.0-openjdk-srcUpgrade java-1.6.0-openjdk-javadocUpgrade java-1.6.0-openjdk-develUpgrade java-1.6.0-openjdk-demo | Oct 16, 2024 | Feb 17, 2011 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Feb 1, 2011 |
| Suse | — | Upgrade java-1_6_0-ibm-alsaUpgrade java-1_6_0-ibm-fontsUpgrade java-1_6_0-ibm-pluginUpgrade java-1_4_2-ibm-sap-develUpgrade java-1_6_0-ibm-jdbcUpgrade java-1_4_2-ibm-pluginUpgrade java-1_6_0-ibmUpgrade java-1_4_2-ibmUpgrade java-1_4_2-ibm-jdbcUpgrade java-1_4_2-ibm-sap | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade openjdk-6-jre-libUpgrade icedtea6-pluginUpgrade openjdk-6-jre-headlessUpgrade openjdk-6-jre | Nov 8, 2024 | Feb 17, 2011 |
| Vmsa 2011 0013 | — | Upgrade VMware ESX 4.1 to build number 502767Upgrade VMware ESX 4.0 to build number 660575 | Nov 22, 2011 | Feb 17, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub