Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sun Java运行时环境Unpack200 JAR解压工具整数溢出漏洞
Vulnerability Description
Solaris系统的Java运行时环境(JRE)为JAVA应用程序提供可靠的运行环境。 JRE中负责处理Pack200压缩JAR文件的代码中存在整数溢出漏洞。在解压过程中,错误的信任了Pack200头中的一些字段用于计算堆缓冲区分配的大小。如果用户受骗访问了恶意的压缩文件或网页,就会触发这个溢出,导致执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A