CVE-2005-0471
Summary
| CVE | CVE-2005-0471 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-03-14 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Sun Java JRE 1.1.x through 1.4.x writes temporary files with long filenames that become predictable on a file system that uses 8.3 style short names, which allows remote attackers to write arbitrary files to known locations and facilitates the exploitation of vulnerabilities in applications that rely on unpredictable file names. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sun | Jdk | 1.1.0 | All | All | All |
| Application | Sun | Jdk | 1.2.0 | All | All | All |
| Application | Sun | Jdk | 1.3.0 | All | All | All |
| Application | Sun | Jdk | 1.4.0 | All | All | All |
| Application | Sun | Jdk | 1.5.0 | All | All | All |
| Application | Sun | Jre | 1.1 | All | All | All |
| Application | Sun | Jre | 1.2 | All | All | All |
| Application | Sun | Jre | 1.3.0 | All | All | All |
| Application | Sun | Jre | 1.4 | All | All | All |
| Application | Sun | Jre | 1.5.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Secunia - Advisories - Sun Java Plugin Predictable File Location Weakness | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| US-CERT Vulnerability Note VU#544392 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.