CVE Vulnerabilities

CVE-2007-2789

Published: May 22, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_19 and earlier, when running on Unix/Linux systems, allows remote attackers to cause a denial of service (JVM hang) via untrusted applets or applications that open arbitrary local files via a crafted BMP file, such as /dev/tty.

Affected Software

NameVendorStart VersionEnd Version
JdkSun1.5.0 (including)1.5.0 (including)
JdkSun1.5.0-update1 (including)1.5.0-update1 (including)
JdkSun1.5.0-update10 (including)1.5.0-update10 (including)
JdkSun1.5.0-update2 (including)1.5.0-update2 (including)
JdkSun1.5.0-update3 (including)1.5.0-update3 (including)
JdkSun1.5.0-update4 (including)1.5.0-update4 (including)
JdkSun1.5.0-update5 (including)1.5.0-update5 (including)
JdkSun1.5.0-update6 (including)1.5.0-update6 (including)
JdkSun1.5.0-update7 (including)1.5.0-update7 (including)
JdkSun1.5.0-update8 (including)1.5.0-update8 (including)
JdkSun1.5.0-update9 (including)1.5.0-update9 (including)
JdkSun1.6.0 (including)1.6.0 (including)
Extras for RHEL 3RedHatjava-1.4.2-ibm-0:1.4.2.9-1jpp.1.el3*
Extras for RHEL 3RedHatjava-1.4.2-bea-0:1.4.2.16-1jpp.1.el3*
Extras for RHEL 4RedHatjava-1.4.2-ibm-0:1.4.2.9-1jpp.1.el4*
Extras for RHEL 4RedHatjava-1.5.0-ibm-1:1.5.0.5-1jpp.2.el4*
Extras for RHEL 4RedHatjava-1.4.2-bea-0:1.4.2.15-1jpp.2.el4*
Red Hat Network Satellite Server v 4.2RedHatjabberd-0:2.0s10-3.38.rhn*
Red Hat Network Satellite Server v 4.2RedHatjava-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4*
Red Hat Network Satellite Server v 4.2RedHatjfreechart-0:0.9.20-3.rhn*
Red Hat Network Satellite Server v 4.2RedHatopenmotif21-0:2.1.30-11.RHEL4.6*
Red Hat Network Satellite Server v 4.2RedHatperl-Crypt-CBC-0:2.24-1.el4*
Red Hat Network Satellite Server v 4.2RedHatrhn-apache-0:1.3.27-36.rhn.rhel4*
Red Hat Network Satellite Server v 4.2RedHatrhn-modjk-0:1.2.23-2rhn.rhel4*
Red Hat Network Satellite Server v 4.2RedHatrhn-modperl-0:1.29-16.rhel4*
Red Hat Network Satellite Server v 4.2RedHatrhn-modssl-0:2.8.12-8.rhn.10.rhel4*
Red Hat Network Satellite Server v 4.2RedHattomcat5-0:5.0.30-0jpp_10rh*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatjabberd-0:2.0s10-3.37.rhn*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatjava-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatjfreechart-0:0.9.20-3.rhn*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatopenmotif21-0:2.1.30-9.RHEL3.8*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatperl-Crypt-CBC-0:2.24-1.el3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn-apache-0:1.3.27-36.rhn.rhel3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn-modjk-0:1.2.23-2rhn.rhel3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn-modperl-0:1.29-16.rhel3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn-modssl-0:2.8.12-8.rhn.10.rhel3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHattomcat5-0:5.0.30-0jpp_10rh*
Red Hat Network Satellite Server v 5.0RedHatjabberd-0:2.0s10-3.38.rhn*
Red Hat Network Satellite Server v 5.0RedHatjava-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4*
Red Hat Network Satellite Server v 5.0RedHatjfreechart-0:0.9.20-3.rhn*
Red Hat Network Satellite Server v 5.0RedHatopenmotif21-0:2.1.30-11.RHEL4.6*
Red Hat Network Satellite Server v 5.0RedHatperl-Crypt-CBC-0:2.24-1.el4*
Red Hat Network Satellite Server v 5.0RedHatrhn-apache-0:1.3.27-36.rhn.rhel4*
Red Hat Network Satellite Server v 5.0RedHatrhn-modjk-0:1.2.23-2rhn.rhel4*
Red Hat Network Satellite Server v 5.0RedHatrhn-modperl-0:1.29-16.rhel4*
Red Hat Network Satellite Server v 5.0RedHatrhn-modssl-0:2.8.12-8.rhn.10.rhel4*
Red Hat Network Satellite Server v 5.0RedHattomcat5-0:5.0.30-0jpp_10rh*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.4.2-ibm-0:1.4.2.9-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-ibm-1:1.5.0.5-1jpp.0.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-bea-0:1.5.0.11-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.4.2-bea-0:1.4.2.16-1jpp.1.el5*
Sun-java6Ubuntudevel*
Sun-java6Ubuntufeisty*
Sun-java6Ubuntugutsy*
Sun-java6Ubuntuhardy*

References