First published: Thu Dec 04 2008(Updated: )
Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows remote attackers to make unauthorized network connections and hijack HTTP sessions via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR" and CR 6707535.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun JDK | =5.0-update_12 | |
Sun JRE | =6 | |
Sun JRE | =1.4.2_7 | |
Sun JDK | =5.0-update_15 | |
Sun JDK | <=5.0 | |
Sun JRE | =1.4.2_16 | |
Sun JDK | =5.0-update_3 | |
Sun JRE | =5.0-update_13 | |
Sun JRE | =5.0-update_1 | |
Sun JDK | =5.0-update_11 | |
Sun JRE | =1.4.2_4 | |
Sun SDK | =1.4.2_10 | |
Sun SDK | =1.4.2_12 | |
Sun JRE | =1.4.2_2 | |
Sun JDK | =6-update_6 | |
Sun JDK | =6-update_7 | |
Sun JDK | =5.0-update_8 | |
Sun JRE | =5.0-update_14 | |
Sun JRE | =6-update_3 | |
Sun JRE | =6-update_4 | |
Sun JRE | =5.0-update_12 | |
Sun SDK | =1.4.2_17 | |
Sun SDK | =1.4.2_14 | |
Sun JDK | =5.0-update_1 | |
Sun JRE | =1.4.2_15 | |
Sun JDK | =6-update_1 | |
Sun JDK | =6 | |
Sun JDK | =6-update_3 | |
Sun JRE | =1.4.2_13 | |
Sun JRE | =1.4.2_1 | |
Sun JDK | =6-update_9 | |
Sun SDK | =1.4.2_13 | |
Sun JRE | =1.4.2_8 | |
Sun JDK | =5.0-update_5 | |
Sun SDK | =1.4.2_6 | |
Sun JRE | =6-update_2 | |
Sun JRE | =5.0-update_4 | |
Sun JRE | =6-update_9 | |
Sun JDK | =6-update_4 | |
Sun SDK | <=1.4.2_18 | |
Sun JRE | <=1.4.2_18 | |
Sun SDK | =1.4.2_2 | |
Sun SDK | =1.4.2_5 | |
Sun JRE | =5.0-update_9 | |
Sun JRE | =1.4.2_12 | |
Sun SDK | =1.4.2_1 | |
Sun JRE | =5.0-update_8 | |
Sun JRE | <=6 | |
Sun JDK | <=6 | |
Sun JRE | =5.0-update_7 | |
Sun JDK | =5.0-update_6 | |
Sun JRE | =5.0-update_15 | |
Sun SDK | =1.4.2_4 | |
Sun JRE | =1.4.2_14 | |
Sun JRE | =6-update_5 | |
Sun JDK | =5.0-update_14 | |
Sun JDK | =6-update_8 | |
Sun JRE | =5.0-update_2 | |
Sun JRE | =1.4.2_10 | |
Sun JRE | <=5.0 | |
Sun JRE | =1.4.2_17 | |
Sun JDK | =6-update_2 | |
Sun SDK | =1.4.2_7 | |
Sun JRE | =6-update_7 | |
Sun JRE | =6-update_8 | |
Sun SDK | =1.4.2_8 | |
Sun JDK | =5.0-update_13 | |
Sun JRE | =5.0-update_5 | |
Sun JRE | =1.4.2_9 | |
Sun SDK | =1.4.2_16 | |
Sun SDK | =1.4.2_11 | |
Sun JRE | =5.0-update_6 | |
Sun JRE | =5.0-update_11 | |
Sun JRE | =1.4.2_11 | |
Sun SDK | =1.4.2_9 | |
Sun JRE | =6-update_1 | |
Sun JDK | =6-update_5 | |
Sun JDK | =5.0-update_10 | |
Sun SDK | =1.4.2_3 | |
Sun JRE | =1.4.2_3 | |
Sun JRE | =1.4.2_5 | |
Sun JDK | =5.0-update_2 | |
Sun JRE | =5.0 | |
Sun SDK | =1.4.2_15 | |
Sun JDK | =5.0-update_4 | |
Sun JDK | =5.0-update_9 | |
Sun JRE | =6-update_6 | |
Sun JRE | =5.0-update_3 | |
Sun JRE | =1.4.2_6 | |
Sun JRE | =5.0-update_10 | |
Sun JDK | =5.0-update_7 | |
redhat/java | <1.4.2-ibm-0:1.4.2.13-1jpp.1.el3 | 1.4.2-ibm-0:1.4.2.13-1jpp.1.el3 |
redhat/java | <1.6.0-sun-1:1.6.0.11-1jpp.1.el4 | 1.6.0-sun-1:1.6.0.11-1jpp.1.el4 |
redhat/java | <1.5.0-sun-0:1.5.0.17-1jpp.2.el4 | 1.5.0-sun-0:1.5.0.17-1jpp.2.el4 |
redhat/java | <1.5.0-ibm-1:1.5.0.9-1jpp.4.el4 | 1.5.0-ibm-1:1.5.0.9-1jpp.4.el4 |
redhat/java | <1.6.0-ibm-1:1.6.0.4-1jpp.1.el4 | 1.6.0-ibm-1:1.6.0.4-1jpp.1.el4 |
redhat/java | <1.4.2-ibm-0:1.4.2.13-1jpp.1.el4 | 1.4.2-ibm-0:1.4.2.13-1jpp.1.el4 |
redhat/java | <1.6.0-sun-1:1.6.0.11-1jpp.1.el5 | 1.6.0-sun-1:1.6.0.11-1jpp.1.el5 |
redhat/java | <1.5.0-sun-0:1.5.0.17-1jpp.2.el5 | 1.5.0-sun-0:1.5.0.17-1jpp.2.el5 |
redhat/java | <1.5.0-ibm-1:1.5.0.9-1jpp.2.el5 | 1.5.0-ibm-1:1.5.0.9-1jpp.2.el5 |
redhat/java | <1.6.0-ibm-1:1.6.0.4-1jpp.1.el5 | 1.6.0-ibm-1:1.6.0.4-1jpp.1.el5 |
redhat/java | <1.4.2-ibm-0:1.4.2.13-1jpp.1.el5 | 1.4.2-ibm-0:1.4.2.13-1jpp.1.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)