FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-5232

This CVE name corresponds to:

Entered Topic
2007-10-08 jdk/jre -- Applet Caching May Allow Network Access Restrictions to be Circumvented

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-5232
Phase Assigned(20071005)

Description

Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack.

References

Source Reference
BUGTRAQ 20071029 FLEA-2007-0061-1 sun-jre sun-jdk
MISC http://conference.hitb.org/hitbsecconf2007kl/?page_id=148
MISC http://conference.hitb.org/hitbsecconf2007kl/materials/D2T1%20-%20Billy%20Rios%20-%20Slipping%20Past%20the%20Firewall.pdf
MISC http://docs.info.apple.com/article.html?artnum=307177
CONFIRM http://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.html
CONFIRM http://www.vmware.com/security/advisories/VMSA-2008-0010.html
APPLE APPLE-SA-2007-12-14
BEA BEA08-198.00
GENTOO GLSA-200804-20
GENTOO GLSA-200804-28
GENTOO GLSA-200806-11
HP HPSBUX02284
HP SSRT071483
REDHAT RHSA-2007:0963
REDHAT RHSA-2007:1041
REDHAT RHSA-2008:0132
REDHAT RHSA-2008:0156
REDHAT RHSA-2008:0100
SUNALERT 103079
SUNALERT 201519
SUSE SUSE-SA:2007:055
SUSE SUSE-SA:2008:025
CERT-VN VU#336105
BID 25918
OVAL oval:org.mitre.oval:def:9331
VUPEN ADV-2007-3895
VUPEN ADV-2007-4224
VUPEN ADV-2008-0609
VUPEN ADV-2008-1856
SECTRACK 1018768
SECUNIA 27206
SECUNIA 27261
SECUNIA 27716
SECUNIA 27693
SECUNIA 27804
SECUNIA 28115
SECUNIA 28777
SECUNIA 28880
SECUNIA 29042
SECUNIA 29214
SECUNIA 29340
SECUNIA 29858
SECUNIA 29897
SECUNIA 30676
SECUNIA 30780
XF sun-java-appletcaching-security-bypass(36941)