CVE-2007-3716: Input Validation
The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3716?
CVE-2007-3716 has a severity rating that allows context-dependent attackers to execute arbitrary code, making it a significant security risk.
How do I fix CVE-2007-3716?
To fix CVE-2007-3716, update the Sun JDK or JRE to version 6 Update 2 or later.
What software is affected by CVE-2007-3716?
CVE-2007-3716 affects Sun JDK and JRE version 6 before Update 2.
What is the impact of CVE-2007-3716?
The impact of CVE-2007-3716 includes the potential for arbitrary code execution through a crafted XSLT stylesheet.
Are there any related vulnerabilities to CVE-2007-3716?
Yes, CVE-2007-3716 is related to CVE-2007-3715, as both involve issues with processing XML signatures.