Sun Java Media Framework (JMF) 2.1.1 through 2.1.1c allows unsigned applets to cause a denial of service (JVM crash) and read or write unauthorized memory locations via the ReadEnv class, as demonstrated by reading environment variables using modified .data and .size fields.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jmf | Sun | 2.1.1 (including) | 2.1.1 (including) |
Jmf | Sun | 2.1.1a (including) | 2.1.1a (including) |
Jmf | Sun | 2.1.1b (including) | 2.1.1b (including) |
Jmf | Sun | 2.1.1c (including) | 2.1.1c (including) |