Vulnerability Description
The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Jdk | <= 1.6.0 |
| Sun | Jre | <= 1.3.1 |
| Sun | Sdk | <= 1.4.2_15 |
References
- http://dev2dev.bea.com/pub/advisory/272
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533
- http://osvdb.org/40834
- http://secunia.com/advisories/27320PatchVendor Advisory
- http://secunia.com/advisories/27693
- http://secunia.com/advisories/29042
- http://secunia.com/advisories/29858
- http://secunia.com/advisories/30676
- http://secunia.com/advisories/30780
- http://security.gentoo.org/glsa/glsa-200804-28.xml
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103112-1Patch
- http://support.avaya.com/elmodocs2/security/ASA-2007-480.htm
- http://www.gentoo.org/security/en/glsa/glsa-200804-20.xml
- http://www.gentoo.org/security/en/glsa/glsa-200806-11.xml
- http://www.securityfocus.com/bid/26185
FAQ
What is CVE-2007-5689?
CVE-2007-5689 is a vulnerability with a CVSS score of 10.0 (HIGH). The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Updat...
How severe is CVE-2007-5689?
CVE-2007-5689 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5689?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Jdk, Sun Jre, Sun Sdk.