Sun Java Runtime Environment Web Start JNLP File Stack Buffer Overflow Vulnerability
BID:24832
Info
Sun Java Runtime Environment Web Start JNLP File Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 24832 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3655 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2007 12:00AM |
| Updated: | Mar 19 2015 08:48AM |
| Credit: | Daniel Soeder working with eEye Digital Security and Brett Moore of Security-Assessment.com are credited with the discovery of this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise Desktop 10 SP1 Sun JRE (Linux Production Release) 1.5 _07 Sun JRE (Linux Production Release) 1.5 _06 Sun JRE (Linux Production Release) 1.5 _05 Sun JRE (Linux Production Release) 1.5 _04 Sun JRE (Linux Production Release) 1.5 _03 Sun JRE (Linux Production Release) 1.5 _02 Sun JRE (Linux Production Release) 1.5 _01 Sun JRE (Linux Production Release) 1.5 Sun JRE (Linux Production Release) 1.6.0_01 Sun JRE (Linux Production Release) 1.5.0_10 Sun JRE (Linux Production Release) 1.5.0_09 Sun JRE (Linux Production Release) 1.5.0_08 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 RedHat Enterprise Linux Extras 4 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Desktop Supplementary 5 client Gentoo Linux Gentoo dev-java/ibm-jre-bin 1.5.0.6 Gentoo dev-java/ibm-jre-bin 1.4.2.10 Gentoo dev-java/ibm-jdk-bin 1.5.0.6 Gentoo dev-java/ibm-jdk-bin 1.4.2.10 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 |
| Not Vulnerable: |
Sun JRE (Linux Production Release) 1.6.0_02 Sun JRE (Linux Production Release) 1.5.0_12 Gentoo dev-java/ibm-jre-bin 1.5.0.7 Gentoo dev-java/ibm-jre-bin 1.4.2.11 Gentoo dev-java/ibm-jdk-bin 1.5.0.7 Gentoo dev-java/ibm-jdk-bin 1.4.2.11 |
Discussion
Sun Java Runtime Environment Web Start JNLP File Stack Buffer Overflow Vulnerability
Sun Java Runtime Environment is prone to a stack-based buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will likely result in a denial-of-service condition.
This issue affects these versions:
Java Runtime Environment 6 update 1
Java Runtime Environment 5 update 11
Prior versions are also affected.
Sun Java Runtime Environment is prone to a stack-based buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application. Failed exploit attempts will likely result in a denial-of-service condition.
This issue affects these versions:
Java Runtime Environment 6 update 1
Java Runtime Environment 5 update 11
Prior versions are also affected.
Exploit / POC
Sun Java Runtime Environment Web Start JNLP File Stack Buffer Overflow Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept code is available:
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept code is available:
Solution / Fix
Sun Java Runtime Environment Web Start JNLP File Stack Buffer Overflow Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Apple Mac OS X 10.4.10
Apple Mac OS X Server 10.4.10
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.4.11
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Apple Mac OS X 10.4.10
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
Apple Mac OS X Server 10.4.10
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
Apple Mac OS X Server 10.4.11
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
Apple Mac OS X 10.4.11
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
References
Sun Java Runtime Environment Web Start JNLP File Stack Buffer Overflow Vulnerability
References:
References:
- RHSA-2007:0818-2 - Critical: java-1.5.0-sun security update (RedHat)
- RHSA-2007:0829-2 - Critical: java-1.5.0-ibm security update (RedHat)
- Sun Java Homepage (Sun Microsystems)
- Sun Java WebStart JNLP Stack Buffer Overflow Vulnerability (eEye Digital Security)
- EEYE: Sun Java WebStart JNLP Stack Buffer Overflow Vulnerability (eEye Advisories)
- SUN Java JNLP Overflow (Brett Moore)
- About the security content of Java Release 6 for Mac OS X 10.4 (Apple)
- Sun Alert ID: 102996 - Security Vulnerability in Java Web Start URL Parsing Code (Sun Microsystems)