Vulnerability Description
Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Jdk | <= 1.5.0 |
| Sun | Jre | <= 1.4.2 |
| Sun | Sdk | <= 1.4.2_14 |
References
- http://dev2dev.bea.com/pub/advisory/248
- http://docs.info.apple.com/article.html?artnum=307177
- http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.html
- http://secunia.com/advisories/26402
- http://secunia.com/advisories/26631
- http://secunia.com/advisories/26933
- http://secunia.com/advisories/27203
- http://secunia.com/advisories/27716
- http://secunia.com/advisories/28056
- http://secunia.com/advisories/28115
- http://secunia.com/advisories/28777
- http://secunia.com/advisories/28880
- http://secunia.com/advisories/29340
- http://secunia.com/advisories/29897
FAQ
What is CVE-2007-4381?
CVE-2007-4381 is a vulnerability with a CVSS score of 9.3 (HIGH). Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions ...
How severe is CVE-2007-4381?
CVE-2007-4381 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4381?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Jdk, Sun Jre, Sun Sdk.