Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this involves an incorrect sign extension in the HeadspaceSoundbank.nGetName function, which allows attackers to execute arbitrary code via a crafted BANK record that leads to a buffer overflow.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Redhat |
|
Sun |
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Configuration 3 [-]
|
Configuration 4 [-]
|
Configuration 5 [-]
|
Configuration 6 [-]
|
Configuration 7 [-]
|
Configuration 8 [-]
|
Configuration 9 [-]
|
Package | CPE | Advisory | Released Date |
---|---|---|---|
Extras for RHEL 4 | |||
java-1.6.0-sun-1:1.6.0.22-1jpp.1.el4 | cpe:/a:redhat:rhel_extras:4 | RHSA-2010:0770 | 2010-10-14T00:00:00Z |
java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el4 | cpe:/a:redhat:rhel_extras:4 | RHSA-2010:0807 | 2010-10-27T00:00:00Z |
Red Hat Enterprise Linux 6 Supplementary | |||
java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el6 | cpe:/a:redhat:rhel_extras:6 | RHSA-2010:0873 | 2010-11-10T00:00:00Z |
Supplementary for Red Hat Enterprise Linux 5 | |||
java-1.6.0-sun-1:1.6.0.22-1jpp.1.el5 | cpe:/a:redhat:rhel_extras:5 | RHSA-2010:0770 | 2010-10-14T00:00:00Z |
java-1.5.0-ibm-1:1.5.0.12.2-1jpp.1.el5 | cpe:/a:redhat:rhel_extras:5 | RHSA-2010:0807 | 2010-10-27T00:00:00Z |
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: oracle
Published: 2010-10-19T21:00:00
Updated: 2024-08-07T03:11:44.350Z
Reserved: 2010-09-20T00:00:00
Link: CVE-2010-3559
Vulnrichment
No data.
NVD
Status : Modified
Published: 2010-10-19T22:00:03.157
Modified: 2024-11-21T01:19:05.923
Link: CVE-2010-3559
Redhat