CVE-2007-2788
published 2007-05-22CVE-2007-2788: Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java…
PriorityP346medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
18.19%
96.9th percentile
Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file that triggers a buffer overflow.
Affected
76 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect delivery of crafted JPEG or BMP files containing malicious embedded ICC profiles targeting Java parsers; monitor for JVM crashes triggered by such files. ↗
- →Flag use of Sun JDK 1.5.0_07-b03 as a known vulnerable version in asset inventory and network traffic (e.g., User-Agent strings or JNLP negotiation). ↗
- →CVE-2007-3004 (IBM JDK ICC profile parser integer overflow) is a duplicate of this CVE; detections for either should be unified under CVE-2007-2788. ↗
- ·Vulnerability affects multiple JDK/JRE release trains; ensure patching covers all branches: JDK/JRE 6 before 1.6.0_01-b06, JDK/JRE 5.0 Update 10 and earlier, SDK/JRE 1.4.2_14 and earlier, and SDK/JRE 1.3.1_20 and earlier. ↗
- ·IBM JDK is also affected via the same ICC profile parser integer overflow (originally tracked as CVE-2007-3004, now merged into CVE-2007-2788); IBM JDK deployments must be patched separately. ↗
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit
vendor_redhat·2007-05-21·CVSS 6.8
CVE-2007-2788 [MEDIUM] CWE-190 Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit
Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit
Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file that triggers a buffer overflow.
Red Hat
IBM JDK: Integer overflow in IBM JDK's ICC profile parser
vendor_redhat·2007-04-15·CVSS 6.8
CVE-2007-3004 [MEDIUM] CWE-190 IBM JDK: Integer overflow in IBM JDK's ICC profile parser
IBM JDK: Integer overflow in IBM JDK's ICC profile parser
[REJECTED CVE] This CVE has been rejected. This candidate is a duplicate of CVE-2007-2788. Note: All CVE users should reference CVE-2007-2788 instead of this candidate.
GHSA
GHSA-cjwj-wvcj-rr5c: Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1
ghsa_unreviewed·2022-05-01
CVE-2007-2788 [MEDIUM] GHSA-cjwj-wvcj-rr5c: Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1
Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file that triggers a buffer overflow.
No detection rules found.
No writeups or analysis indexed.
http://dev2dev.bea.com/pub/advisory/248http://docs.info.apple.com/article.html?artnum=307177http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000003.htmlhttp://scary.beasts.org/security/CESA-2006-004.htmlhttp://secunia.com/advisories/25295http://secunia.com/advisories/25474http://secunia.com/advisories/25832http://secunia.com/advisories/26049http://secunia.com/advisories/26119http://secunia.com/advisories/26311http://secunia.com/advisories/26369http://secunia.com/advisories/26631http://secunia.com/advisories/26645http://secunia.com/advisories/26933http://secunia.com/advisories/27203http://secunia.com/advisories/27266http://secunia.com/advisories/28056http://secunia.com/advisories/28115http://secunia.com/advisories/28365http://secunia.com/advisories/29340http://secunia.com/advisories/29858http://secunia.com/advisories/30780http://secunia.com/advisories/30805http://security.gentoo.org/glsa/glsa-200706-08.xmlhttp://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-102934-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200856-1http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.htmlhttp://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.htmlhttp://www.attrition.org/pipermail/vim/2007-December/001862.htmlhttp://www.attrition.org/pipermail/vim/2007-July/001696.htmlhttp://www.attrition.org/pipermail/vim/2007-July/001697.htmlhttp://www.attrition.org/pipermail/vim/2007-July/001708.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200705-23.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200709-15.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.kb.cert.org/vuls/id/138545http://www.novell.com/linux/security/advisories/2007_45_java.htmlhttp://www.novell.com/linux/security/advisories/2007_56_ibmjava.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0817.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0829.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0956.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1086.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0100.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0133.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0261.htmlhttp://www.securityfocus.com/bid/24004http://www.securityfocus.com/bid/24267http://www.securitytracker.com/id?1018182http://www.vupen.com/english/advisories/2007/1836http://www.vupen.com/english/advisories/2007/3009http://www.vupen.com/english/advisories/2007/4224http://www.vupen.com/english/advisories/2008/0065https://exchange.xforce.ibmcloud.com/vulnerabilities/34318https://exchange.xforce.ibmcloud.com/vulnerabilities/34652https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11700http://dev2dev.bea.com/pub/advisory/248http://docs.info.apple.com/article.html?artnum=307177http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000003.htmlhttp://scary.beasts.org/security/CESA-2006-004.htmlhttp://secunia.com/advisories/25295http://secunia.com/advisories/25474http://secunia.com/advisories/25832http://secunia.com/advisories/26049http://secunia.com/advisories/26119http://secunia.com/advisories/26311http://secunia.com/advisories/26369http://secunia.com/advisories/26631http://secunia.com/advisories/26645http://secunia.com/advisories/26933http://secunia.com/advisories/27203http://secunia.com/advisories/27266http://secunia.com/advisories/28056http://secunia.com/advisories/28115http://secunia.com/advisories/28365http://secunia.com/advisories/29340http://secunia.com/advisories/29858http://secunia.com/advisories/30780http://secunia.com/advisories/30805http://security.gentoo.org/glsa/glsa-200706-08.xmlhttp://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-102934-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200856-1http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.htmlhttp://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.htmlhttp://www.attrition.org/pipermail/vim/2007-December/001862.htmlhttp://www.attrition.org/pipermail/vim/2007-July/001696.htmlhttp://www.attrition.org/pipermail/vim/2007-July/001697.htmlhttp://www.attrition.org/pipermail/vim/2007-July/001708.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200705-23.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200709-15.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.kb.cert.org/vuls/id/138545http://www.novell.com/linux/security/advisories/2007_45_java.htmlhttp://www.novell.com/linux/security/advisories/2007_56_ibmjava.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0817.html
+ 16 more references
2007-05-22
Published