CVE-2007-5273
Anti-DNS Pinning and Java Applets with HTTP proxy
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy server is used, allows remote attackers to violate the security model for an applet's outbound connections via a multi-pin DNS rebinding attack in which the applet download relies on DNS resolution on the proxy server, but the applet's socket operations rely on DNS resolution on the local machine, a different issue than CVE-2007-5274. NOTE: this is similar to CVE-2007-5232.
En Sun Java Runtime Environment (JRE) en JDK y JRE versión 6 Update 2 y anteriores, JDK y JRE versión 5.0 Update 12 y anteriores, SDK y JRE versión 1.4.2_15 y anteriores, y SDK y JRE versión 1.3.1_20 y anteriores, cuando un servidor proxy HTTP se utiliza, permite a los atacantes remotos violar el modelo de seguridad para las conexiones salientes de un applets por medio de un ataque de reajuste de múlti-pin DNS en el que la descarga del applet depende de la resolución DNS en el servidor proxy, pero las operaciones de socket del applet dependen de la resolución DNS en máquina local, un problema diferente de CVE-2007-5274. NOTA: esto es similar a CVE-2007-5232.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-10-08 CVE Reserved
- 2007-10-08 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (39)
URL | Tag | Source |
---|---|---|
http://crypto.stanford.edu/dns/dns-rebinding.pdf | X_refsource_misc | |
http://osvdb.org/45527 | Vdb Entry | |
http://seclists.org/fulldisclosure/2007/Jul/0159.html | Mailing List | |
http://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.html | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/482926/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/25918 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10340 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://securitytracker.com/id?1018771 | 2018-10-30 | |
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103078-1 | 2018-10-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update1 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update10 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update11 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update12 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update2 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update3 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update4 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update5 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update7 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update8 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.5.0 Search vendor "Sun" for product "Jdk" and version "1.5.0" | update9 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.6.0 Search vendor "Sun" for product "Jdk" and version "1.6.0" | update1 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.6.0 Search vendor "Sun" for product "Jdk" and version "1.6.0" | update2 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.0 Search vendor "Sun" for product "Jre" and version "1.3.0" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.0 Search vendor "Sun" for product "Jre" and version "1.3.0" | update5 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1 Search vendor "Sun" for product "Jre" and version "1.3.1" | update1 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1 Search vendor "Sun" for product "Jre" and version "1.3.1" | update16 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1 Search vendor "Sun" for product "Jre" and version "1.3.1" | update18 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1 Search vendor "Sun" for product "Jre" and version "1.3.1" | update19 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1 Search vendor "Sun" for product "Jre" and version "1.3.1" | update1a |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.3.1 Search vendor "Sun" for product "Jre" and version "1.3.1" | update20 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4 Search vendor "Sun" for product "Jre" and version "1.4" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.1 Search vendor "Sun" for product "Jre" and version "1.4.1" | update3 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2 Search vendor "Sun" for product "Jre" and version "1.4.2" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_1 Search vendor "Sun" for product "Jre" and version "1.4.2_1" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_3 Search vendor "Sun" for product "Jre" and version "1.4.2_3" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_8 Search vendor "Sun" for product "Jre" and version "1.4.2_8" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_9 Search vendor "Sun" for product "Jre" and version "1.4.2_9" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_10 Search vendor "Sun" for product "Jre" and version "1.4.2_10" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_11 Search vendor "Sun" for product "Jre" and version "1.4.2_11" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_12 Search vendor "Sun" for product "Jre" and version "1.4.2_12" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_13 Search vendor "Sun" for product "Jre" and version "1.4.2_13" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_14 Search vendor "Sun" for product "Jre" and version "1.4.2_14" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.4.2_15 Search vendor "Sun" for product "Jre" and version "1.4.2_15" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update1 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update10 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update11 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update12 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update2 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update3 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update4 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update5 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update6 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update7 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update8 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.5.0 Search vendor "Sun" for product "Jre" and version "1.5.0" | update9 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.6.0 Search vendor "Sun" for product "Jre" and version "1.6.0" | update_1 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 1.6.0 Search vendor "Sun" for product "Jre" and version "1.6.0" | update_2 |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_01 Search vendor "Sun" for product "Sdk" and version "1.3.1_01" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_01a Search vendor "Sun" for product "Sdk" and version "1.3.1_01a" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_16 Search vendor "Sun" for product "Sdk" and version "1.3.1_16" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_18 Search vendor "Sun" for product "Sdk" and version "1.3.1_18" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_19 Search vendor "Sun" for product "Sdk" and version "1.3.1_19" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.3.1_20 Search vendor "Sun" for product "Sdk" and version "1.3.1_20" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2 Search vendor "Sun" for product "Sdk" and version "1.4.2" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_03 Search vendor "Sun" for product "Sdk" and version "1.4.2_03" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_08 Search vendor "Sun" for product "Sdk" and version "1.4.2_08" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_09 Search vendor "Sun" for product "Sdk" and version "1.4.2_09" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_10 Search vendor "Sun" for product "Sdk" and version "1.4.2_10" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_11 Search vendor "Sun" for product "Sdk" and version "1.4.2_11" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_12 Search vendor "Sun" for product "Sdk" and version "1.4.2_12" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_13 Search vendor "Sun" for product "Sdk" and version "1.4.2_13" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_14 Search vendor "Sun" for product "Sdk" and version "1.4.2_14" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sdk Search vendor "Sun" for product "Sdk" | 1.4.2_15 Search vendor "Sun" for product "Sdk" and version "1.4.2_15" | - |
Affected
|