CVE-2010-0843
Summary
| CVE | CVE-2010-0843 |
|---|---|
| State | PUBLISHED |
| Assigner | oracle |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-04-01 16:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to XNewPtr and improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, which allows remote attackers to execute arbitrary code. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sun | Jdk | 1.5.0 | update23 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_18 | All | All |
| Application | Sun | Jre | 1.3.1_27 | All | All | All |
| Application | Sun | Jre | 1.4.2_25 | All | All | All |
| Application | Sun | Jre | 1.5.0 | update23 | All | All |
| Application | Sun | Jre | 1.6.0 | update_18 | All | All |
| Application | Sun | Sdk | 1.3.1_27 | All | All | All |
| Application | Sun | Sdk | 1.4.2_25 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| osvdb.org/63492 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| About the security content of Java for Mac OS X 10.5 Update 7 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Bugtraq: ZDI-10-052: Sun Java Runtime Environment XNewPtr Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Oracle Java SE and Java for Business 'XNewPtr()' Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| VMware vCenter Server 4.1 Update 1 Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | |
| Oracle Critical Patch Update Pre-Release Announcement - October 2010 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| SUSE Update for Multiple Packages - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Apple Mac OS X update for Java - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| '[security bulletin] HPSBUX02524 SSRT100089 rev.1 - HP-UX Running Java, Remote Execution of Arbitrary' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| VMSA-2011-0003 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | |
| APPLE-SA-2010-05-18-1 Java for Mac OS X 10.6 Update 2 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Red Hat update for java-1.5.0-ibm - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Red Hat update for java-1.6.0-ibm - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Support | Red Hat | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| '[security bulletin] HPSBMU02799 SSRT100867 rev.1 - HP Network Node Manager i (NNMi) v9.0x Running JD' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| VMware vCenter / ESX Server Update for Oracle (Sun) JRE - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Oracle Java SE and Java for Business Critical Patch Update Advisory - March 2010 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| About the security content of Java for Mac OS X 10.6 Update 2 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:008 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| HP Systems Insight Manager Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:017 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| itrc.hp.com/service/cki/docDisplay.do | af854a3a-2127-422b-91ae-364da2661108 | itrc.hp.com | |
| APPLE-SA-2010-05-18-2 Java for Mac OS X 10.5 Update 7 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.