Vulnerabilities in Java Web Start allow to determine the location of the Java Web Start cache
Published Oct 6, 2007
2.6
LOWCVSS 2.0
EPSS 2.66%
Description
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka "three vulnerabilities."
Affected products
No data.
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.6.0
- 1.6.0
- 1.3.0
- 1.3.0
- 1.3.1
- 1.3.1
- 1.3.1
- 1.3.1
- 1.3.1
- 1.3.1
- 1.4
- 1.4.1
- 1.4.2
- 1.4.2_1
- 1.4.2_3
- 1.4.2_8
- 1.4.2_9
- 1.4.2_10
- 1.4.2_11
- 1.4.2_12
- 1.4.2_13
- 1.4.2_14
- 1.4.2_15
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.6.0
- 1.6.0
- 1.3.1_01
- 1.3.1_01a
- 1.3.1_16
- 1.3.1_18
- 1.3.1_19
- 1.3.1_20
- 1.4.2
- 1.4.2_03
- 1.4.2_08
- 1.4.2_09
- 1.4.2_10
- 1.4.2_11
- 1.4.2_12
- 1.4.2_13
- 1.4.2_14
- 1.4.2_15
No data.
Extras for RHEL 3
java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3
Fixed · RHSA-2008:0132
Extras for RHEL 4
java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
Fixed · RHSA-2008:0132
Extras for RHEL 4
java-1.5.0-ibm-1:1.5.0.6-1jpp.2.el4
Fixed · RHSA-2007:1041
Extras for RHEL 4
java-1.5.0-sun-0:1.5.0.13-1jpp.1.el4
Fixed · RHSA-2007:0963
Supplementary for Red Hat Enterprise Linux 5
java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el5
Fixed · RHSA-2008:0132
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-ibm-1:1.5.0.6-1jpp.1.el5
Fixed · RHSA-2007:1041
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-sun-0:1.5.0.13-1jpp.1.el5
Fixed · RHSA-2007:0963
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 3 | java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3 | Fixed | RHSA-2008:0132 |
| Extras for RHEL 4 | java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4 | Fixed | RHSA-2008:0132 |
| Extras for RHEL 4 | java-1.5.0-ibm-1:1.5.0.6-1jpp.2.el4 | Fixed | RHSA-2007:1041 |
| Extras for RHEL 4 | java-1.5.0-sun-0:1.5.0.13-1jpp.1.el4 | Fixed | RHSA-2007:0963 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el5 | Fixed | RHSA-2008:0132 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-ibm-1:1.5.0.6-1jpp.1.el5 | Fixed | RHSA-2007:1041 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-sun-0:1.5.0.13-1jpp.1.el5 | Fixed | RHSA-2007:0963 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (38)
- http://dev2dev.bea.com/pub/advisory/272 vendor-advisoryx_refsource_BEA
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533 vendor-advisoryx_refsource_HP
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/27206 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27261 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27693 third-party-advisoryx_refsource_SECUNIAPatch
- http://secunia.com/advisories/27716 third-party-advisoryx_refsource_SECUNIAPatch
- http://secunia.com/advisories/27804 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28777 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28880 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29042 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29858 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29897 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30676 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30780 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200804-28.xml vendor-advisoryx_refsource_GENTOO
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103073-1 vendor-advisoryx_refsource_SUNALERTPatch
- http://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.html x_refsource_CONFIRM
- http://www.gentoo.org/security/en/glsa/glsa-200804-20.xml vendor-advisoryx_refsource_GENTOO
- http://www.gentoo.org/security/en/glsa/glsa-200806-11.xml vendor-advisoryx_refsource_GENTOO
- http://www.novell.com/linux/security/advisories/2007_55_java.html vendor-advisoryx_refsource_SUSE
- http://www.redhat.com/support/errata/RHSA-2007-0963.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-1041.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0132.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/482926/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/25920 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1018770 vdb-entryx_refsource_SECTRACK
- http://www.vmware.com/security/advisories/VMSA-2008-0010.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2007/3895 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/0609 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/1856/references vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2007-5238 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=321961 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2007-5218 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36946 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2007-5238
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11592 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2007-5238
Change history (0)
No recorded changes yet.