Sun.Java.Web.Start.Encoding.Stack.Buffer.Overflow

description-logoDescription

This indicates an attempt to exploit a stack buffer overflow vulnerability in Sun Java Web Start.
The vulnerability is caused by an input validation error in the "useEncodingDecl()" function. The error occurs while parsing the XML header's character encoding attribute. It allows remote attackers to execute arbitrary code via an over long "charset" name.

affected-products-logoAffected Products

Sun JDK and JRE 6 Update 4 and earlier.
Sun JDK and JRE 5.0 Update 14 and earlier.

Impact logoImpact

System Compromise: remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Refer to the vendor's web site for a suggested workaround.
http://sunsolve.sun.com/search/document.do?assetkey=1-66-233323-1

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)