Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SUN Java Update 代码注入漏洞
Vulnerability Description
Java是由Sun 公司于1995年5月推出的Java程序设计语言和Java平台的总称。 Sun Java 1.6.0_03和之前的版本以及可能后来的版本都没有正确地校验更新的真实性,导致恶意代码注入漏洞。通过中间人攻击方式,可以利用此漏洞在升级中使用包含木马的更新,执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A