CVE-2007-2789: Medium severity Java Development Kit (JDK) vulnerability
The BMP image parser in Sun Java Development Kit (JDK) before 1.5.011-b03 and 1.6.x before 1.6.001-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.214 and earlier, and SDK and JRE 1.3.119 and earlier, when running on Unix/Linux systems, allows remote attackers to cause a denial of service (JVM hang) via untrusted applets or applications that open arbitrary local files via a crafted BMP file, such as /dev/tty.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2789?
CVE-2007-2789 is rated as a high severity vulnerability due to its potential impact on systems using vulnerable versions of Java.
How do I fix CVE-2007-2789?
To fix CVE-2007-2789, you should update your Java Development Kit (JDK) or Java Runtime Environment (JRE) to the latest available version.
What software versions are affected by CVE-2007-2789?
CVE-2007-2789 affects several versions of Sun JDK and JRE including 1.5.0 before update 11-b03 and 1.6.x before update 01-b06.
Is CVE-2007-2789 exploitable remotely?
Yes, CVE-2007-2789 can be exploited remotely by attackers through specially crafted BMP images.
What types of systems are primarily impacted by CVE-2007-2789?
CVE-2007-2789 primarily impacts Unix and Linux systems that are running vulnerable versions of the Java Development Kit or Java Runtime Environment.