BEA07-172.00Vendor advisory
http://dev2dev.bea.com/pub/advisory/242 CVE-2007-0243
Sun Microsystems Java - '.GIF' File Parsing Memory Corruption
Record summary
CVE-2007-0243 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSun Microsystems Java - '.GIF' File Parsing Memory CorruptionExploitDB exploitby luoluoNot analyzed1 file
References
Showing 12 of 41docs.info.apple.com
http://docs.info.apple.com/article.html?artnum=307177 HPSBUX02196Vendor advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00876579 APPLE-SA-2007-12-14Vendor advisory
http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html 32834vdb entry
http://osvdb.org/32834 23757Third-party advisory
http://secunia.com/advisories/23757 24189Third-party advisory
http://secunia.com/advisories/24189 24202Third-party advisory
http://secunia.com/advisories/24202 24468Third-party advisory
http://secunia.com/advisories/24468 24993Third-party advisory
http://secunia.com/advisories/24993 25283Third-party advisory
http://secunia.com/advisories/25283 26049Third-party advisory
http://secunia.com/advisories/26049