CVE-2006-0617
published 2006-02-09CVE-2006-0617: Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 5 and earlier allow remote attackers to bypass Java sandbox security and obtain…
PriorityP423medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
3.80%
88.8th percentile
Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 5 and earlier allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "fifth, sixth, and seventh issues."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.5.0 | — |
| sun | jre | <= 1.5.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-3745 Local SCTP privilege escalation
bugzilla·2006-08-10·CVSS 7.2
CVE-2006-3745 [HIGH] CVE-2006-3745 Local SCTP privilege escalation
CVE-2006-3745 Local SCTP privilege escalation
Report from Wei Wang of McAfee Avert Labs:
A locally exploitable flaw has been found in the Linux sctp module
sctp_make_abort_user function that allows local users to gain root privileges
and also execute arbitrary code at kernel privilege level.
Discussion:
committed in kernel 42.0.2
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0617.html
---
committed in stream U5 build 42.4. A test kernel with this patch is av
Bugzilla
CVE-2004-2660 O_DIRECT write sometimes leaks memory
bugzilla·2006-05-15·CVSS 4.9
CVE-2004-2660 [MEDIUM] CVE-2004-2660 O_DIRECT write sometimes leaks memory
CVE-2004-2660 O_DIRECT write sometimes leaks memory
It seems that O_DIRECT write sometimes leaks memory.
The upstream fix can be found here:
http://linux.bkbits.net:8080/linux-2.6/cset@4182a613oVsK0-8eCWpyYFrUf8rhLA
Discussion:
committed in stream E5 build 42.0.1. A test kernel with this patch is available
from http://people.redhat.com/~jbaron/rhel4/
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0617.html
---
committed in stream U5 build 42.4. A test kernel
http://docs.info.apple.com/article.html?artnum=303658http://secunia.com/advisories/18760http://secunia.com/advisories/18884http://securitytracker.com/id?1015596http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1http://www.gentoo.org/security/en/glsa/glsa-200602-07.xmlhttp://www.kb.cert.org/vuls/id/759996http://www.vupen.com/english/advisories/2006/0467http://www.vupen.com/english/advisories/2006/0828http://www.vupen.com/english/advisories/2006/1398https://exchange.xforce.ibmcloud.com/vulnerabilities/24561http://docs.info.apple.com/article.html?artnum=303658http://secunia.com/advisories/18760http://secunia.com/advisories/18884http://securitytracker.com/id?1015596http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1http://www.gentoo.org/security/en/glsa/glsa-200602-07.xmlhttp://www.kb.cert.org/vuls/id/759996http://www.vupen.com/english/advisories/2006/0467http://www.vupen.com/english/advisories/2006/0828http://www.vupen.com/english/advisories/2006/1398https://exchange.xforce.ibmcloud.com/vulnerabilities/24561
2006-02-09
Published