Bugraq ID: 35944 Sun Java Runtime Environment是一款为JAVA应用程序提供可靠的运行环境的解决方案。 Sun Java Runtime Environment负责处理Pack200压缩JAR文件的代码存在缺陷,远程攻击者可以利用漏洞以登录用户安全上下文执行任意指令。 在解压缩过程中,Pack200头字段的多个字段被盲目信任,并用于计算堆缓冲区分配的大小,通过提供恶意值攻击者可以建立很小的堆缓冲区,并在之后的拷贝过程中溢出缓冲区,构建恶意WEB页,诱使用户打开可导致以登录用户安全上下文执行任意指令。 Sun JRE (Windows Production Release) 1.5 _06 Sun JRE (Windows Production Release) 1.5 _05 Sun JRE (Windows Production Release) 1.5 _04 Sun JRE (Windows Production Release) 1.5 _03 Sun JRE (Windows Production Release) 1.5 _02 Sun JRE (Windows Production Release) 1.5 _01 Sun JRE (Windows Production Release) 1.5 Sun JRE (Windows Production Release) 1.5.0_17 Sun JRE (Windows Production Release) 1.5.0_14 Sun JRE (Windows Production Release) 1.5.0_13 Sun JRE (Windows Production Release) 1.5.0_12 Sun JRE (Windows Production Release) 1.5.0_11 Sun JRE (Windows Production Release) 1.5.0_10 Sun JRE (Windows Production Release) 1.5.0_10 Sun JRE (Windows Production Release) 1.5.0.0_09 Sun JRE (Windows Production Release)...
Bugraq ID: 35944 Sun Java Runtime Environment是一款为JAVA应用程序提供可靠的运行环境的解决方案。 Sun Java Runtime Environment负责处理Pack200压缩JAR文件的代码存在缺陷,远程攻击者可以利用漏洞以登录用户安全上下文执行任意指令。 在解压缩过程中,Pack200头字段的多个字段被盲目信任,并用于计算堆缓冲区分配的大小,通过提供恶意值攻击者可以建立很小的堆缓冲区,并在之后的拷贝过程中溢出缓冲区,构建恶意WEB页,诱使用户打开可导致以登录用户安全上下文执行任意指令。 Sun JRE (Windows Production Release) 1.5 _06 Sun JRE (Windows Production Release) 1.5 _05 Sun JRE (Windows Production Release) 1.5 _04 Sun JRE (Windows Production Release) 1.5 _03 Sun JRE (Windows Production Release) 1.5 _02 Sun JRE (Windows Production Release) 1.5 _01 Sun JRE (Windows Production Release) 1.5 Sun JRE (Windows Production Release) 1.5.0_17 Sun JRE (Windows Production Release) 1.5.0_14 Sun JRE (Windows Production Release) 1.5.0_13 Sun JRE (Windows Production Release) 1.5.0_12 Sun JRE (Windows Production Release) 1.5.0_11 Sun JRE (Windows Production Release) 1.5.0_10 Sun JRE (Windows Production Release) 1.5.0_10 Sun JRE (Windows Production Release) 1.5.0.0_09 Sun JRE (Windows Production Release) 1.5.0.0_08 Sun JRE (Windows Production Release) 1.5.0.0_07 Sun JRE (Solaris Production Release) 1.5 _06 Sun JRE (Solaris Production Release) 1.5 _05 Sun JRE (Solaris Production Release) 1.5 _04 Sun JRE (Solaris Production Release) 1.5 _03 Sun JRE (Solaris Production Release) 1.5 _02 Sun JRE (Solaris Production Release) 1.5 _01 Sun JRE (Solaris Production Release) 1.5 Sun JRE (Solaris Production Release) 1.5.0_17 Sun JRE (Solaris Production Release) 1.5.0_14 Sun JRE (Solaris Production Release) 1.5.0_13 Sun JRE (Solaris Production Release) 1.5.0_12 Sun JRE (Solaris Production Release) 1.5.0_11 Sun JRE (Solaris Production Release) 1.5.0_10 Sun JRE (Solaris Production Release) 1.5.0.0_09 Sun JRE (Solaris Production Release) 1.5.0.0_08 Sun JRE (Solaris Production Release) 1.5.0.0_07 Sun JRE (Linux Production Release) 1.5 _07 Sun JRE (Linux Production Release) 1.5 _06 Sun JRE (Linux Production Release) 1.5 _05 Sun JRE (Linux Production Release) 1.5 _04 Sun JRE (Linux Production Release) 1.5 _03 Sun JRE (Linux Production Release) 1.5 _02 Sun JRE (Linux Production Release) 1.5 _01 Sun JRE (Linux Production Release) 1.5 .0 beta Sun JRE (Linux Production Release) 1.5 Sun JRE (Linux Production Release) 1.5.0_17 Sun JRE (Linux Production Release) 1.5.0_14 Sun JRE (Linux Production Release) 1.5.0_13 Sun JRE (Linux Production Release) 1.5.0_13 Sun JRE (Linux Production Release) 1.5.0_12 Sun JRE (Linux Production Release) 1.5.0_12 Sun JRE (Linux Production Release) 1.5.0_11 Sun JRE (Linux Production Release) 1.5.0_10 Sun JRE (Linux Production Release) 1.5.0_09 Sun JRE (Linux Production Release) 1.5.0_08 Sun JRE 6.0 Update 7 Sun JRE 6.0 Update 6 Sun JRE 6.0 Update 5 Sun JRE 6.0 Update 4 Sun JRE 6.0 Update 3 Sun JRE 6.0 Update 2 Sun JRE 6.0 Update 14 Sun JRE 6.0 Update 13 Sun JRE 6.0 Update 12 Sun JRE 6.0 Update 11 Sun JRE 6.0 Update 10 Sun JRE 6.0 Update 1 Sun JRE 5.0 Update 9 Sun JRE 5.0 Update 8 Sun JRE 5.0 Update 7 Sun JRE 5.0 Update 6 Sun JRE 5.0 Update 18 Sun JRE 5.0 Update 17 Sun JRE 5.0 Update 16 Sun JRE 5.0 Update 15 Sun JRE 5.0 Update 15 Sun JRE 5.0 Update 14 Sun JRE 5.0 Update 13 Sun JRE 5.0 Update 12 Sun JRE 5.0 Update 11 Sun JRE 5.0 Update 10 Sun JDK (Windows Production Release) 1.6.0_03 Sun JDK (Windows Production Release) 1.6.0_02 Sun JDK (Windows Production Release) 1.6.0_01-b06 Sun JDK (Windows Production Release) 1.6.0_01 Sun JDK (Solaris Production Release) 1.6.0_03 Sun JDK (Solaris Production Release) 1.6.0_02 Sun JDK (Solaris Production Release) 1.6.0_01 Sun JDK (Linux Production Release) 1.6.0_03 Sun JDK (Linux Production Release) 1.6.0_02 Sun JDK (Linux Production Release) 1.6.0_01 Sun JDK 6.0 Update 7 Sun JDK 6.0 Update 6 Sun JDK 6.0 Update 5 Sun JDK 6.0 Update 4 Sun JDK 6.0 Update 3 Sun JDK 6.0 Update 2 Sun JDK 6.0 Update 14 Sun JDK 6.0 Update 13 Sun JDK 6.0 Update 11 Sun JDK 6.0 Update 10 Sun JDK 6.0 Update 1 Sun JDK 6.0 Sun JDK 5.0 Update 8 Sun JDK 5.0 Update 7 Sun JDK 5.0 Update 6 Sun JDK 5.0 Update 5 Sun JDK 5.0 Update 4 Sun JDK 5.0 Update 3 Sun JDK 5.0 Update 2 Sun JDK 5.0 Update 18 Sun JDK 5.0 Update 17 Sun JDK 5.0 Update 16 Sun JDK 5.0 Update 16 Sun JDK 5.0 Update 15 Sun JDK 5.0 Update 15 Sun JDK 5.0 Update 14 Sun JDK 5.0 Update 13 Sun JDK 5.0 Update 12 Sun JDK 5.0 Update 11 Sun JDK 5.0 Update 10 Sun JDK 5.0 Update 1 厂商解决方案 用户可参考如下升级程序: Sun JDK (Windows Production Release) 1.6.0_02 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JRE (Windows Production Release) 1.5.0.0_09 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Windows Production Release) 1.5.0_10 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 5.0 Update 6 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Windows Production Release) 1.5.0.0_08 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 6.0 Update 6 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JRE (Linux Production Release) 1.5.0_12 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 6.0 Update 2 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JDK 5.0 Update 8 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 5.0 Update 4 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Linux Production Release) 1.5.0_13 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 5.0 Update 6 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 5.0 Update 15 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Windows Production Release) 1.5.0_12 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 5.0 Update 14 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 5.0 Update 18 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 6.0 Update 10 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JRE (Windows Production Release) 1.5.0_10 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Linux Production Release) 1.5.0_08 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Windows Production Release) 1.5.0_14 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Linux Production Release) 1.5.0_13 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 5.0 Update 16 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 5.0 Update 2 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK (Windows Production Release) 1.6.0_01 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JRE (Linux Production Release) 1.5.0_10 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Solaris Production Release) 1.5.0.0_07 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 5.0 Update 12 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Solaris Production Release) 1.5.0_13 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Solaris Production Release) 1.5.0_10 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 6.0 Update 14 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JRE (Solaris Production Release) 1.5.0_11 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 5.0 Update 13 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 6.0 Update 13 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JRE 5.0 Update 14 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 5.0 Update 5 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 6.0 Update 3 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JRE 6.0 Update 7 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JDK 5.0 Update 7 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 6.0 Update 4 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JDK (Linux Production Release) 1.6.0_02 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JRE (Windows Production Release) 1.5.0.0_07 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 6.0 Update 14 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JRE (Linux Production Release) 1.5.0_11 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 5.0 Update 17 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 5.0 Update 18 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Windows Production Release) 1.5.0_17 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 5.0 Update 17 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 5.0 Update 13 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Linux Production Release) 1.5.0_17 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK (Linux Production Release) 1.6.0_03 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JRE 6.0 Update 2 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JRE 5.0 Update 11 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK 6.0 Update 11 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JRE (Windows Production Release) 1.5.0_13 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 6.0 Update 5 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JDK 5.0 Update 16 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 5.0 Update 15 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 5.0 Update 12 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 5.0 Update 8 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 5.0 Update 9 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK (Windows Production Release) 1.6.0_03 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JRE (Solaris Production Release) 1.5.0_17 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Solaris Production Release) 1.5.0.0_09 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 5.0 Update 10 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE 6.0 Update 4 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JDK 5.0 Update 11 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JDK (Linux Production Release) 1.6.0_01 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JDK 6.0 Update 1 Sun JDK and JRE 6 Update 15 http://java.sun.com/javase/downloads/index.jsp Sun JRE (Solaris Production Release) 1.5 _05 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Linux Production Release) 1.5 _01 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Solaris Production Release) 1.5 _01 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Solaris Production Release) 1.5 _03 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Windows Production Release) 1.5 _01 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Windows Production Release) 1.5 _05 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Solaris Production Release) 1.5 _02 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Linux Production Release) 1.5 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Windows Production Release) 1.5 _02 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Linux Production Release) 1.5 _03 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Windows Production Release) 1.5 _03 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Windows Production Release) 1.5 _06 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Solaris Production Release) 1.5 Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp Sun JRE (Linux Production Release) 1.5 .0 beta Sun JDK and JRE 5.0 Update 20 http://java.sun.com/javase/downloads/index_jdk5.jsp