Описание
Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | not-affected | |
gutsy | DNE | |
hardy | released | 6b18-1.8.2-4ubuntu1~8.04.1 |
intrepid | released | 6b12-0ubuntu6.4 |
jaunty | not-affected | |
karmic | not-affected | |
lucid | not-affected | |
maverick | not-affected | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | ignored | end of life |
devel | DNE | |
gutsy | ignored | end of life, was needs-triage |
hardy | not-affected | |
intrepid | ignored | end of life, was needs-triage |
jaunty | not-affected | |
karmic | DNE | |
lucid | DNE | |
maverick | DNE | |
upstream | not-affected |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | DNE | |
gutsy | ignored | end of life, was needs-triage |
hardy | released | 6.20dlj-0ubuntu1.8.04 |
intrepid | ignored | end of life, was needs-triage |
jaunty | released | 6.20dlj-0ubuntu1.9.04 |
karmic | released | 6.20dlj-0ubuntu1.9.10 |
lucid | released | 6.20dlj-1ubuntu3 |
maverick | not-affected | |
upstream | released | 6.13 |
Показывать по
EPSS
9.3 Critical
CVSS2
Связанные уязвимости
Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.
Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.
Multiple buffer overflows in Java SE Development Kit (JDK) and Java Ru ...
Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.
ELSA-2009-0377: java-1.6.0-openjdk security update (IMPORTANT)
EPSS
9.3 Critical
CVSS2