CVE-2007-2788: Buffer Overflow
Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.011-b03 and 1.6.x before 1.6.001-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.214 and earlier, and SDK and JRE 1.3.120 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file that triggers a buffer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2788?
CVE-2007-2788 is rated as high severity due to the potential for an attacker to exploit the integer overflow in the ICC profile image parser, leading to arbitrary code execution.
How do I fix CVE-2007-2788?
To resolve CVE-2007-2788, you should update to JDK versions 1.5.0_11-b03, 1.6.0_01-b06, or later.
Which versions are affected by CVE-2007-2788?
CVE-2007-2788 affects JDK versions before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, including various 1.4.2 and 1.3.1 versions.
What type of vulnerability is CVE-2007-2788?
CVE-2007-2788 is an integer overflow vulnerability found in the embedded ICC profile image parser.
What are the potential impacts of CVE-2007-2788?
The exploitation of CVE-2007-2788 can lead to arbitrary code execution, allowing attackers to gain unauthorized control over a vulnerable system.