First published: Mon Oct 29 2007(Updated: )
The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun JRE | =1.3.1-update1a | |
Sun SDK | =1.4.2 | |
Sun SDK | =1.3.1_19 | |
OpenJDK | <=1.6.0 | |
Sun JRE | =1.3.1-update19 | |
Sun SDK | =1.4.2_10 | |
Sun SDK | =1.4.2_12 | |
OpenJDK | =1.5.0-update3 | |
Sun JRE | =1.4.1-update3 | |
Sun JRE | =1.5.0-update2 | |
Sun SDK | =1.4.2_14 | |
Sun JRE | =1.6.0-update_1 | |
Sun JRE | =1.6.0-update_2 | |
Sun JRE | =1.4.2_13 | |
Sun JRE | =1.4.2_1 | |
Sun SDK | =1.4.2_13 | |
Sun JRE | =1.4.2_8 | |
OpenJDK | =1.5.0-update11 | |
Sun JRE | =1.5.0-update8 | |
OpenJDK | =1.5.0-update9 | |
Sun JRE | =1.4.2_12 | |
Sun JRE | =1.5.0-update11 | |
Sun JRE | =1.3.1-update1 | |
Sun JRE | <=1.3.1 | |
Sun JRE | =1.3.0-update5 | |
Sun SDK | =1.3.1_20 | |
Sun SDK | =1.3.1_18 | |
Sun SDK | =1.3.1_01 | |
Sun JRE | =1.4.2_14 | |
Sun JRE | =1.5.0-update7 | |
Sun JRE | =1.5.0-update3 | |
Sun SDK | =1.3.1_16 | |
Sun SDK | =1.3.1_01a | |
Sun JRE | <=1.5.0 | |
Sun JRE | =1.3.0 | |
Sun JRE | =1.4.2_10 | |
OpenJDK | =1.5.0-update1 | |
Sun SDK | <=1.4.2_15 | |
Sun SDK | =1.4.2_09 | |
Sun JRE | =1.3.1-update16 | |
OpenJDK | =1.5.0-update4 | |
OpenJDK | =1.6.0-update1 | |
Sun JRE | =1.5.0-update5 | |
Sun JRE | =1.4 | |
Sun JRE | <=1.4.2 | |
OpenJDK | =1.5.0-update7 | |
Sun JRE | =1.4.2_9 | |
Sun JRE | =1.4.2 | |
Sun SDK | =1.4.2_11 | |
Sun JRE | =1.5.0-update6 | |
Sun JRE | =1.5.0-update9 | |
Sun JRE | =1.4.2_11 | |
OpenJDK | =1.5.0-update12 | |
Sun JRE | =1.5.0-update1 | |
OpenJDK | =1.5.0-update5 | |
Sun JRE | =1.5.0-update10 | |
OpenJDK | =1.5.0-update2 | |
Sun SDK | =1.4.2_08 | |
Sun SDK | =1.4.2_03 | |
OpenJDK | =1.5.0-update8 | |
Sun JRE | =1.3.1-update18 | |
Sun JRE | =1.4.2_3 | |
Sun JRE | =1.5.0-update4 | |
OpenJDK | =1.5.0-update10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5689 has been classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2007-5689, it is recommended to update the Java Runtime Environment or the Java Development Kit to a version that has addressed this vulnerability.
CVE-2007-5689 allows attackers to execute arbitrary programs or access and modify files on affected software, posing significant security risks.
CVE-2007-5689 affects various versions of the Sun Java Runtime Environment and Java Development Kit, specifically versions 1.3.x through 1.6.x.
While waiting to update, disabling the Java plugin in web browsers can mitigate the risk associated with CVE-2007-5689.