First published: Sat Oct 06 2007(Updated: )
Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, on Windows does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read local files via an untrusted application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun JRE | =1.4.2_7 | |
Sun JRE | =1.4.2_4 | |
Sun SDK | =1.4.2_10 | |
Sun SDK | =1.4.2_12 | |
OpenJDK | =1.5.0-update3 | |
Sun JRE | =1.4.2_2 | |
Sun JRE | =1.5.0-update2 | |
Sun SDK | =1.4.2_14 | |
Sun JRE | =1.4.2_15 | |
Sun JRE | =1.4.2_13 | |
Sun JRE | =1.4.2_1 | |
Sun SDK | =1.4.2_13 | |
Sun JRE | =1.4.2_8 | |
Sun JRE | =1.5.0-update12 | |
OpenJDK | =1.5.0-update11 | |
Sun JRE | =1.5.0-update8 | |
OpenJDK | =1.5.0-update9 | |
Sun JRE | =1.4.2_12 | |
Sun JRE | =1.5.0-update11 | |
Sun JRE | =1.4.2_14 | |
Sun JRE | =1.5.0-update7 | |
Sun JRE | =1.5.0-update3 | |
Sun JRE | =1.4.2_10 | |
OpenJDK | =1.5.0-update1 | |
Sun SDK | =1.4.2_09 | |
OpenJDK | =1.5.0-update4 | |
Sun JRE | =1.5.0-update5 | |
OpenJDK | =1.5.0-update7 | |
Sun JRE | =1.4.2_9 | |
Sun JRE | =1.4.2 | |
Sun SDK | =1.4.2_11 | |
Sun JRE | =1.5.0-update6 | |
Sun JRE | =1.4.2_21 | |
Sun JRE | =1.5.0-update9 | |
Sun JRE | =1.4.2_11 | |
OpenJDK | =1.5.0-update12 | |
Sun JRE | =1.5.0-update1 | |
OpenJDK | =1.5.0-update5 | |
Sun JRE | =1.5.0-update10 | |
OpenJDK | =1.5.0-update2 | |
Sun SDK | =1.4.2_08 | |
Sun SDK | =1.4.2_03 | |
OpenJDK | =1.5.0-update8 | |
Sun JRE | =1.4.2_3 | |
Sun JRE | =1.5.0-update4 | |
Sun JRE | =1.4.2_5 | |
Sun SDK | =1.4.2_15 | |
Sun JRE | =1.4.2_6 | |
OpenJDK | =1.5.0-update10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5236 is considered a moderate severity vulnerability due to its potential for local file access by untrusted applications.
To fix CVE-2007-5236, upgrade to a patched version of the Sun JDK or JRE that is not vulnerable.
CVE-2007-5236 affects Sun JDK and JRE versions 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier on Windows.
CVE-2007-5236 exploits improper enforcement of access restrictions for untrusted applications.
Users of affected versions of Sun JDK, JRE, and SDK, particularly on Windows, are at risk if they run untrusted applications.