Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow in the color profile parser that allows remote attackers to execute arbitrary code via a crafted Tag structure in a color profile.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Redhat |
|
Sun |
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Configuration 3 [-]
|
Configuration 4 [-]
|
Configuration 5 [-]
|
Configuration 6 [-]
|
Configuration 7 [-]
|
Configuration 8 [-]
|
Configuration 9 [-]
|
Package | CPE | Advisory | Released Date |
---|---|---|---|
Extras for RHEL 3 | |||
java-1.4.2-ibm-0:1.4.2.13.6-1jpp.3.el3 | cpe:/a:redhat:rhel_extras:3 | RHSA-2010:0786 | 2010-10-20T00:00:00Z |
Extras for RHEL 4 | |||
java-1.6.0-sun-1:1.6.0.22-1jpp.1.el4 | cpe:/a:redhat:rhel_extras:4 | RHSA-2010:0770 | 2010-10-14T00:00:00Z |
java-1.4.2-ibm-0:1.4.2.13.6-1jpp.2.el4 | cpe:/a:redhat:rhel_extras:4 | RHSA-2010:0786 | 2010-10-20T00:00:00Z |
java-1.6.0-ibm-1:1.6.0.9.0-1jpp.3.el4 | cpe:/a:redhat:rhel_extras:4 | RHSA-2010:0987 | 2010-12-15T00:00:00Z |
java-1.5.0-ibm-1:1.5.0.12.3-1jpp.1.el4 | cpe:/a:redhat:rhel_extras:4 | RHSA-2011:0169 | 2011-01-20T00:00:00Z |
Red Hat Enterprise Linux 6 Supplementary | |||
java-1.6.0-ibm-1:1.6.0.9.0-1jpp.4.el6 | cpe:/a:redhat:rhel_extras:6 | RHSA-2010:0987 | 2010-12-15T00:00:00Z |
java-1.5.0-ibm-1:1.5.0.12.3-1jpp.2.el6 | cpe:/a:redhat:rhel_extras:6 | RHSA-2011:0169 | 2011-01-20T00:00:00Z |
Red Hat Network Satellite Server v 5.4 | |||
java-1.6.0-ibm-1:1.6.0.9.1-1jpp.1.el5 | cpe:/a:redhat:network_satellite:5.4::el5 | RHSA-2011:0880 | 2011-06-16T00:00:00Z |
RHEL 4 for SAP | |||
java-1.4.2-ibm-sap-0:1.4.2.13.6.sap-1jpp.1.el4_8 | cpe:/a:redhat:rhel_extras_sap:4 | RHSA-2010:0986 | 2010-12-15T00:00:00Z |
RHEL 5 for SAP | |||
java-1.4.2-ibm-sap-0:1.4.2.13.6.sap-1jpp.1.el5 | cpe:/a:redhat:rhel_extras_sap:5 | RHSA-2010:0986 | 2010-12-15T00:00:00Z |
Supplementary for Red Hat Enterprise Linux 5 | |||
java-1.6.0-sun-1:1.6.0.22-1jpp.1.el5 | cpe:/a:redhat:rhel_extras:5 | RHSA-2010:0770 | 2010-10-14T00:00:00Z |
java-1.4.2-ibm-0:1.4.2.13.6-1jpp.2.el5 | cpe:/a:redhat:rhel_extras:5 | RHSA-2010:0786 | 2010-10-20T00:00:00Z |
java-1.6.0-ibm-1:1.6.0.9.0-1jpp.3.el5 | cpe:/a:redhat:rhel_extras:5 | RHSA-2010:0987 | 2010-12-15T00:00:00Z |
java-1.5.0-ibm-1:1.5.0.12.3-1jpp.1.el5 | cpe:/a:redhat:rhel_extras:5 | RHSA-2011:0169 | 2011-01-20T00:00:00Z |
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: oracle
Published: 2010-10-19T21:00:00
Updated: 2024-08-07T03:11:44.585Z
Reserved: 2010-09-20T00:00:00
Link: CVE-2010-3571
Vulnrichment
No data.
NVD
Status : Modified
Published: 2010-10-19T22:00:03.563
Modified: 2024-11-21T01:19:08.297
Link: CVE-2010-3571
Redhat