Title : Sun Java Runtime Environment GIF Image Handling Remote Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-0211 CVE ID : CVE-2007-0243
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-17
Technical Description
A vulnerability has been identified in Sun Java Runtime Environment, which could be exploited by remote attackers to take complete control of an affected system. This issue is due to a buffer overflow error when parsing GIF images with a "width" property set to 0, which could be exploited by remote attackers to read and write local files on a vulnerable system or execute local applications by tricking a user into visiting a malicious web page containing a specially crafted applet.