header-logo
Suggest Exploit
vendor:
Sun Java JRE
by:
jduck
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Sun Java JRE
Affected Version From: 1.3.1_26
Affected Version To: 1.6.0_16
Patch Exists: YES
Related CWE: CVE-2009-3869
CPE: a:oracle:java:1.6.0_16
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3, Linux, Mac OS X
2009

Sun Java JRE AWT setDiffICM Buffer Overflow

This module exploits a flaw in the setDiffICM function in the Sun JVM. The payload is serialized and passed to the applet via PARAM tags. It must be a native payload. The effected Java versions are JDK and JRE 6 Update 16 and earlier, JDK and JRE 5.0 Update 21 and earlier, SDK and JRE 1.4.2_23 and earlier, and SDK and JRE 1.3.1_26 and earlier.

Mitigation:

Upgrade to the latest version of Sun Java JRE
Source

Exploit-DB raw data: