CVE-2007-2789
BMP image parser vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_19 and earlier, when running on Unix/Linux systems, allows remote attackers to cause a denial of service (JVM hang) via untrusted applets or applications that open arbitrary local files via a crafted BMP file, such as /dev/tty.
El analizador de imágenes BMP en Sun Java Development Kit (JDK) versiones anteriores a 1.5.0_11-b03 y versiones 1.6.x anteriores a 1.6.0_01-b06, y Sun Java Runtime Environment en JDK y JRE versión 6, JDK y JRE versión 5.0 Update 10 y anteriores, SDK y JRE versión 1.4.2_14 y anteriores, y SDK y JRE versión 1.3.1_19 y anteriores, cuando se ejecutan en sistemas Unix/Linux, permiten a atacantes remotos causar una denegación de servicio (bloqueo de JVM) por medio de applets o aplicaciones no confiables que abren archivos locales arbitrarios por medio de un archivo BMP diseñado, tales como /dev/tty.
A buffer overflow vulnerability in the image parsing code in the Java Runtime Environment may allow an untrusted applet or application to elevate its privileges. For example, an applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet. A second vulnerability may allow an untrusted applet or application to cause the Java Virtual Machine to hang. The first vulnerability affects JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier. The second vulnerability affects JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_19 and earlier.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-05-21 CVE Reserved
- 2007-05-22 CVE Published
- 2024-08-07 CVE Updated
- 2025-06-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (52)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/25295 | 2019-08-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update1 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update10 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update2 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update3 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update4 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update5 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update6 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update7 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update8 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update9 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.6.0 Search vendor "Sun" for product "Jdk" and version "1.6.0" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1 Search vendor "Sun" for product "Jre" and version "1.3.1" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_2 Search vendor "Sun" for product "Jre" and version "1.3.1_2" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_03 Search vendor "Sun" for product "Jre" and version "1.3.1_03" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_04 Search vendor "Sun" for product "Jre" and version "1.3.1_04" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_05 Search vendor "Sun" for product "Jre" and version "1.3.1_05" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_06 Search vendor "Sun" for product "Jre" and version "1.3.1_06" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_07 Search vendor "Sun" for product "Jre" and version "1.3.1_07" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_08 Search vendor "Sun" for product "Jre" and version "1.3.1_08" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_09 Search vendor "Sun" for product "Jre" and version "1.3.1_09" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_10 Search vendor "Sun" for product "Jre" and version "1.3.1_10" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_11 Search vendor "Sun" for product "Jre" and version "1.3.1_11" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_12 Search vendor "Sun" for product "Jre" and version "1.3.1_12" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_13 Search vendor "Sun" for product "Jre" and version "1.3.1_13" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_14 Search vendor "Sun" for product "Jre" and version "1.3.1_14" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_15 Search vendor "Sun" for product "Jre" and version "1.3.1_15" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_16 Search vendor "Sun" for product "Jre" and version "1.3.1_16" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_17 Search vendor "Sun" for product "Jre" and version "1.3.1_17" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_18 Search vendor "Sun" for product "Jre" and version "1.3.1_18" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1_19 Search vendor "Sun" for product "Jre" and version "1.3.1_19" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2 Search vendor "Sun" for product "Jre" and version "1.4.2" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_1 Search vendor "Sun" for product "Jre" and version "1.4.2_1" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_2 Search vendor "Sun" for product "Jre" and version "1.4.2_2" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_3 Search vendor "Sun" for product "Jre" and version "1.4.2_3" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_4 Search vendor "Sun" for product "Jre" and version "1.4.2_4" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_5 Search vendor "Sun" for product "Jre" and version "1.4.2_5" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_6 Search vendor "Sun" for product "Jre" and version "1.4.2_6" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_7 Search vendor "Sun" for product "Jre" and version "1.4.2_7" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_8 Search vendor "Sun" for product "Jre" and version "1.4.2_8" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_9 Search vendor "Sun" for product "Jre" and version "1.4.2_9" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_10 Search vendor "Sun" for product "Jre" and version "1.4.2_10" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_11 Search vendor "Sun" for product "Jre" and version "1.4.2_11" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_12 Search vendor "Sun" for product "Jre" and version "1.4.2_12" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_13 Search vendor "Sun" for product "Jre" and version "1.4.2_13" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_14 Search vendor "Sun" for product "Jre" and version "1.4.2_14" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update1 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update10 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update2 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update3 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update4 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update5 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update6 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update7 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update8 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update9 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.6.0 Search vendor "Sun" for product "Jre" and version "1.6.0" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1 Search vendor "Sun" for product "Sdk" and version "1.3.1" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_01 Search vendor "Sun" for product "Sdk" and version "1.3.1_01" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_01a Search vendor "Sun" for product "Sdk" and version "1.3.1_01a" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_02 Search vendor "Sun" for product "Sdk" and version "1.3.1_02" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_03 Search vendor "Sun" for product "Sdk" and version "1.3.1_03" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_04 Search vendor "Sun" for product "Sdk" and version "1.3.1_04" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_05 Search vendor "Sun" for product "Sdk" and version "1.3.1_05" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_06 Search vendor "Sun" for product "Sdk" and version "1.3.1_06" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_07 Search vendor "Sun" for product "Sdk" and version "1.3.1_07" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_08 Search vendor "Sun" for product "Sdk" and version "1.3.1_08" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_09 Search vendor "Sun" for product "Sdk" and version "1.3.1_09" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_10 Search vendor "Sun" for product "Sdk" and version "1.3.1_10" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_11 Search vendor "Sun" for product "Sdk" and version "1.3.1_11" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_12 Search vendor "Sun" for product "Sdk" and version "1.3.1_12" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_13 Search vendor "Sun" for product "Sdk" and version "1.3.1_13" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_14 Search vendor "Sun" for product "Sdk" and version "1.3.1_14" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_15 Search vendor "Sun" for product "Sdk" and version "1.3.1_15" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_16 Search vendor "Sun" for product "Sdk" and version "1.3.1_16" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_17 Search vendor "Sun" for product "Sdk" and version "1.3.1_17" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_18 Search vendor "Sun" for product "Sdk" and version "1.3.1_18" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_19 Search vendor "Sun" for product "Sdk" and version "1.3.1_19" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2 Search vendor "Sun" for product "Sdk" and version "1.4.2" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_1 Search vendor "Sun" for product "Sdk" and version "1.4.2_1" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_2 Search vendor "Sun" for product "Sdk" and version "1.4.2_2" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_3 Search vendor "Sun" for product "Sdk" and version "1.4.2_3" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_4 Search vendor "Sun" for product "Sdk" and version "1.4.2_4" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_5 Search vendor "Sun" for product "Sdk" and version "1.4.2_5" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_6 Search vendor "Sun" for product "Sdk" and version "1.4.2_6" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_7 Search vendor "Sun" for product "Sdk" and version "1.4.2_7" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_8 Search vendor "Sun" for product "Sdk" and version "1.4.2_8" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_9 Search vendor "Sun" for product "Sdk" and version "1.4.2_9" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_10 Search vendor "Sun" for product "Sdk" and version "1.4.2_10" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_11 Search vendor "Sun" for product "Sdk" and version "1.4.2_11" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_12 Search vendor "Sun" for product "Sdk" and version "1.4.2_12" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_13 Search vendor "Sun" for product "Sdk" and version "1.4.2_13" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_14 Search vendor "Sun" for product "Sdk" and version "1.4.2_14" | - |
Affected
|