First published: Mon Jun 01 2009(Updated: )
Sun Java Media Framework (JMF) 2.1.1 through 2.1.1c allows unsigned applets to cause a denial of service (JVM crash) and read or write unauthorized memory locations via the ReadEnv class, as demonstrated by reading environment variables using modified .data and .size fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Jmf | =2.1.1b | |
Sun Jmf | =2.1.1 | |
Sun Jmf | =2.1.1c | |
Sun Jmf | =2.1.1a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1572 has a high severity rating due to its potential for causing denial of service and unauthorized memory access.
To fix CVE-2003-1572, upgrade to the latest version of Sun Java Media Framework that addresses this vulnerability.
CVE-2003-1572 affects Sun Java Media Framework versions 2.1.1, 2.1.1a, 2.1.1b, and 2.1.1c.
CVE-2003-1572 is a denial of service vulnerability that also allows unauthorized reading and writing of memory locations.
Yes, unsigned applets can exploit CVE-2003-1572 to cause a crash in the JVM and potentially manipulate memory.