LWN.net Logo

sun-jdk: arbitrary code execution

Package(s):sun-jdk CVE #(s):CVE-2007-0243
Created:February 19, 2007 Updated:April 25, 2007
Description: A anonymous researcher discovered that an error in the handling of a GIF image with a zero width field block leads to a memory corruption flaw. An attacker could entice a user to run a specially crafted Java applet or application that would load a crafted GIF image, which could result in escalation of privileges and unauthorized access to system resources.
Alerts:
Red Hat RHSA-2007:0167-01 2007-04-25
Red Hat RHSA-2007:0166-01 2007-04-25
Gentoo 200702-08 2007-02-17
Gentoo 200702-07 2007-02-17

(Log in to post comments)

sun-jdk: arbitrary code execution

Posted Feb 25, 2007 18:45 UTC (Sun) by kreutzm (guest, #4700) [Link]

Sun's jdk is not part of Debian Sarge.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds