CVE-2007-0012

Publication date 9 January 2008

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

Description

Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.

Read the notes from the security team

Status

Package Ubuntu Release Status
sun-java5 9.10 karmic Not in release
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life
sun-java6 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy Ignored end of life, was needs-triage
7.04 feisty Ignored end of life, was needs-triage
6.10 edgy Not in release
6.06 LTS dapper Not in release

Notes


jdstrand

browser bug and almost definitely Windows specific


mdeslaur

advisory says java6 is not affected


Access our resources on patching vulnerabilities