Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2010-03-30.2

iDefense Security Advisory 03.30.10 – Remote exploitation of a buffer overflow vulnerability in Oracle Corp.’s (formerly Sun Microsystems Inc.) Java Runtime Environment (JRE) could allow an attacker to execute arbitrary code with the privileges of the current user. The JRE is a platform that supports the execution of programs that are developed using the Java programming language. It is available for multiple platforms, including Windows, Linux and MacOS. The JRE platform also supports Java Applets, which can be loaded from Web pages. During the processing of an image file, user-controlled data is trusted and can result in an undersized allocation of a heap buffer. A copy operation into the heap buffer can lead to a heap overflow condition within the JRE. This condition may allow a remote attacker to subvert execution control and execute arbitrary code.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/87876/03.30.10-2.txt

Source: https://packetstormsecurity.com/files/87876/iDEFENSE-Security-Advisory-2010-03-30.2.html

Related posts
Advisories

57657.html

Advisories

Secunia Security Advisory 17317

Advisories

Ubuntu Security Notice 284-1

Advisories

Hardened-PHP Project Security Advisory 2006-14.139