Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file that triggers a buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Java | — | Upgrade to Apple Java version 1.5.0.13Upgrade to Apple Java version 1.4.2.16 | Jan 26, 2012 | May 21, 2007 |
| Gentoo Linux | — | Upgrade app-emulation/emul-linux-x86-java.Upgrade dev-java/sun-jdk.Upgrade dev-java/sun-jre-bin.Upgrade dev-java/jrockit-jdk-bin. | Oct 30, 2017 | May 21, 2007 |
| Suse | — | Upgrade java-1_4_2-ibm-jdbcUpgrade java-1_4_2-ibm-pluginUpgrade java-1_4_2-ibm | Feb 17, 2015 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub