漏洞信息详情
Sun Java Runtime Environment Network 访问权限制安全绕过漏洞
- CNNVD编号:CNNVD-200707-397
- 危害等级: 中危
- CVE编号:
CVE-2007-3922
- 漏洞类型:
资料不足
- 发布时间:
2007-07-20
- 威胁类型:
远程
- 更新时间:
2009-08-10
- 厂 商:
sun - 漏洞来源:
The vendor credits… -
漏洞简介
Sun JDK and JRE 5.0 Update 11版本及其早期版本, 6 至6 更新1版本, 以及SDK和JRE 1.4.2_14版本及其早期版本的Java Runtime Environment (JRE) Applet Class Loader中存在未明漏洞。远程攻击者可以通过在机器上运行的与某些加载了applet的本地主机服务,违反applet的对外连接的安全模型。
漏洞公告
参考网址
来源: VUPEN
名称: ADV-2007-2573
链接:http://www.frsirt.com/english/advisories/2007/2573
来源: REDHAT
名称: RHSA-2008:0133
链接:http://www.redhat.com/support/errata/RHSA-2008-0133.html
来源: SUNALERT
名称: 102995
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-102995-1
来源: SECUNIA
名称: 30805
链接:http://secunia.com/advisories/30805
来源: HP
名称: SSRT071465
链接:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01269450
来源: HP
名称: SSRT071465
链接:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01269450
来源: HP
名称: SSRT071465
链接:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01269450
来源: HP
名称: SSRT071465
链接:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01269450
来源: HP
名称: SSRT071465
链接:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01269450
来源: XF
名称: sun-java-class-unauthorized-access(35491)
链接:http://xforce.iss.net/xforce/xfdb/35491
来源: SECTRACK
名称: 1018428
链接:http://www.securitytracker.com/id?1018428
来源: BID
名称: 25054
链接:http://www.securityfocus.com/bid/25054
来源: REDHAT
名称: RHSA-2007:0829
链接:http://www.redhat.com/support/errata/RHSA-2007-0829.html
来源: REDHAT
名称: RHSA-2007:0818
链接:http://www.redhat.com/support/errata/RHSA-2007-0818.html
来源: SUSE
名称: SUSE-SA:2007:056
链接:http://www.novell.com/linux/security/advisories/2007_56_ibmjava.html
来源: GENTOO
名称: GLSA-200709-15
链接:http://www.gentoo.org/security/en/glsa/glsa-200709-15.xml
来源: VUPEN
名称: ADV-2007-4224
链接:http://www.frsirt.com/english/advisories/2007/4224
来源: VUPEN
名称: ADV-2007-3861
链接:http://www.frsirt.com/english/advisories/2007/3861
来源: VUPEN
名称: ADV-2007-3009
链接:http://www.frsirt.com/english/advisories/2007/3009
来源: support.avaya.com
链接:http://support.avaya.com/elmodocs2/security/ASA-2007-322.htm
来源: SLACKWARE
名称: SSA:2007-243-01
链接:http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.486841
来源: SECUNIA
名称: 28115
链接:http://secunia.com/advisories/28115
来源: SECUNIA
名称: 27635
链接:http://secunia.com/advisories/27635
来源: SECUNIA
名称: 27266
链接:http://secunia.com/advisories/27266
来源: SECUNIA
名称: 26933
链接:http://secunia.com/advisories/26933
来源: SECUNIA
名称: 26645
链接:http://secunia.com/advisories/26645
来源: SECUNIA
名称: 26631
链接:http://secunia.com/advisories/26631
来源: SECUNIA
名称: 26369
链接:http://secunia.com/advisories/26369
来源: SECUNIA
名称: 26314
链接:http://secunia.com/advisories/26314
来源: APPLE
名称: APPLE-SA-2007-12-14
链接:http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html
来源: HP
名称: SSRT071465
链接:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01269450
来源: MISC
链接:http://docs.info.apple.com/article.html?artnum=307177
来源: BEA
名称: BEA07-177.00