>> Sun Java Development Kit ICC and BMP Parsing Buffer Overflow and DoS Vulnerabilities
Title : Sun Java Development Kit ICC and BMP Parsing Buffer Overflow and DoS Vulnerabilities VUPEN ID : VUPEN/ADV-2007-1836 CVE ID : CVE-2007-2788 - CVE-2007-2789 - CVE-2007-3004 - CVE-2007-3005
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-05-16
Technical Description
Two vulnerabilities have been identified in Sun Java Development Kit (JDK), which could be exploited by remote attackers to take complete control of an affected system or cause a denial of service.
The first issue is caused by an integer overflow error in the image parser when processing ICC profiles embedded within JPEG images, which could be exploited by attackers to execute arbitrary code.
The second vulnerability is caused by an error in the BMP image parser when processing malformed files on Unix/linux systems, which could be exploited by attackers to cause a denial of service.