RULE(RULE ID:323542)

Rule General Information
Release Date: 2019-10-18
Rule Name: Sun Java Plugin JNLP Codebase Buffer Overflow Vulnerability (CVE-2007-3655)
Severity:
CVE ID:
Rule Protection Details
Description: Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and earlier, allows remote attackers to execute arbitrary code via a long codebase attribute in a JNLP file.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Others
Reference: ExploitDB:30284
SecurityFocusBID:24832
http://docs.info.apple.com/article.html?artnum=307177
http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://java.sun.com/javase/downloads/index.jsp