Sun Java Runtime Environment Nested Array Objects Denial Of Service Vulnerability
BID:18058
Info
Sun Java Runtime Environment Nested Array Objects Denial Of Service Vulnerability
| Bugtraq ID: | 18058 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-1301 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2006 12:00AM |
| Updated: | Dec 08 2015 10:20PM |
| Credit: | Disclosure of this issue is credited to Marc Schoenefeld. |
| Vulnerable: |
Sun JRE (Solaris Production Release) 1.3.1 Sun JRE (Solaris Production Release) 1.3 _04 Sun JRE (Solaris Production Release) 1.3 _03 Sun JRE (Solaris Production Release) 1.3 _01 Sun JRE (Linux Production Release) 1.5 _06 Sun JRE (Linux Production Release) 1.5 _05 Sun JRE (Linux Production Release) 1.5 _04 Sun JRE (Linux Production Release) 1.5 _03 Sun JRE (Linux Production Release) 1.5 _02 Sun JRE (Linux Production Release) 1.5 _01 Sun JRE (Linux Production Release) 1.5 Sun JRE (Linux Production Release) 1.4.2 _10-b03 Sun JRE (Linux Production Release) 1.4.2 _09 Sun JRE (Linux Production Release) 1.4.2 _08 Sun JRE (Linux Production Release) 1.4.2 _07 Sun JRE (Linux Production Release) 1.4.2 _06 Sun JRE (Linux Production Release) 1.4.2 _05 Sun JRE (Linux Production Release) 1.4.2 _04 Sun JRE (Linux Production Release) 1.4.2 _03 Sun JRE (Linux Production Release) 1.4.2 _02 Sun JRE (Linux Production Release) 1.4.2 _01 Sun JRE (Linux Production Release) 1.4.2 Sun JRE (Linux Production Release) 1.4.1 Sun JRE (Linux Production Release) 1.3.1 _17 Sun JRE (Linux Production Release) 1.3.1 _16 Sun JRE (Linux Production Release) 1.3.1 _15 Sun JRE (Linux Production Release) 1.3.1 _08 Sun JRE (Linux Production Release) 1.3.1 _04 Sun JRE (Linux Production Release) 1.3.1 _01a Sun JRE (Linux Production Release) 1.3.1 _01 Sun JRE (Linux Production Release) 1.3 .0_05 Sun JRE (Linux Production Release) 1.3 .0_02 Sun JRE (Linux Production Release) 1.3 .0 Sun JRE (Linux Production Release) 1.4.2_11 |
| Not Vulnerable: | |
Discussion
Sun Java Runtime Environment Nested Array Objects Denial Of Service Vulnerability
The Sun Java Runtime Environment is vulnerable to a denial-of-service vulnerability. This issue is due to the software's failure to handle exceptional conditions.
This issue is reported to affect Java Runtime Environment versions up to 1.4.2_11 and 1.5.0_06. This issue will crash Internet browsers running an affected Java plug-in.
An attacker may exploit this issue to cause a vulnerable application -- as well as all processes spawned from the application -- to crash, denying service to legitimate users. Due to the scope of the crash, data loss may occur.
The Sun Java Runtime Environment is vulnerable to a denial-of-service vulnerability. This issue is due to the software's failure to handle exceptional conditions.
This issue is reported to affect Java Runtime Environment versions up to 1.4.2_11 and 1.5.0_06. This issue will crash Internet browsers running an affected Java plug-in.
An attacker may exploit this issue to cause a vulnerable application -- as well as all processes spawned from the application -- to crash, denying service to legitimate users. Due to the scope of the crash, data loss may occur.
Exploit / POC
Sun Java Runtime Environment Nested Array Objects Denial Of Service Vulnerability
The following proof-of-concept exploit has been provided:
The following proof-of-concept exploit has been provided:
Solution / Fix
Sun Java Runtime Environment Nested Array Objects Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Sun Java Runtime Environment Nested Array Objects Denial Of Service Vulnerability
References:
References:
- Bug ID: 4396719 - Mark Sweep stack overflow on deeply nested Object arrays (Sun Developer Network)
- Bug ID: 4944300 - Hard JVM Crash('Unknown software exception') (Sun Developer Network)
- Java 2 Runtime Environment 1.4 Homepage (Sun Microsystems)
- Generic Browser Crash with Java 1.4.2_11, Java 1.5.0_06 (Marc Schoenefeld)