CVE-2007-5273
published 2007-10-08CVE-2007-5273: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and…
PriorityP414low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
2.68%
84.1th percentile
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy server is used, allows remote attackers to violate the security model for an applet's outbound connections via a multi-pin DNS rebinding attack in which the applet download relies on DNS resolution on the proxy server, but the applet's socket operations rely on DNS resolution on the local machine, a different issue than CVE-2007-5274. NOTE: this is similar to CVE-2007-5232.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.6.0 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | <= 1.3.1 | — |
| sun | jre | <= 1.4.2 | — |
| sun | jre | <= 1.6.0 | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | sdk | <= 1.3.1_20 | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7mgj-mxcg-g7rv: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5
ghsa_unreviewed·2022-05-01·CVSS 4.0
CVE-2007-5273 [MEDIUM] GHSA-7mgj-mxcg-g7rv: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy server is used, allows remote attackers to violate the security model for an applet's outbound connections via a multi-pin DNS rebinding attack in which the applet download relies on DNS resolution on the proxy server, but the applet's socket operations rely on DNS resolution on the local machine, a different issue than CVE-2007-5274. NOTE: this is similar to CVE-2007-5232.
GHSA
GHSA-8686-7jv2-5qvr: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5
ghsa_unreviewed·2022-05-01·CVSS 4.0
CVE-2007-5274 [MEDIUM] GHSA-8686-7jv2-5qvr: Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232.
Red Hat
Anti-DNS Pinning and Java Applets with Opera and Firefox
vendor_redhat·2007-10-04·CVSS 4.0
CVE-2007-5274 [MEDIUM] Anti-DNS Pinning and Java Applets with Opera and Firefox
Anti-DNS Pinning and Java Applets with Opera and Firefox
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232.
Red Hat
Anti-DNS Pinning and Java Applets with HTTP proxy
vendor_redhat·2007-07-09·CVSS 4.0
CVE-2007-5273 [MEDIUM] Anti-DNS Pinning and Java Applets with HTTP proxy
Anti-DNS Pinning and Java Applets with HTTP proxy
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy server is used, allows remote attackers to violate the security model for an applet's outbound connections via a multi-pin DNS rebinding attack in which the applet download relies on DNS resolution on the proxy server, but the applet's socket operations rely on DNS resolution on the local machine, a different issue than CVE-2007-5274. NOTE: this is similar to CVE-2007-5232.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-5375 Java Multi-pin DNS rebinding allows arbitrary Javascript Execution
bugzilla·2008-06-03·CVSS 2.6
CVE-2007-5375 [LOW] CVE-2007-5375 Java Multi-pin DNS rebinding allows arbitrary Javascript Execution
CVE-2007-5375 Java Multi-pin DNS rebinding allows arbitrary Javascript Execution
Interpretation conflict in the Sun Java Virtual Machine (JVM) allows
user-assisted remote attackers to conduct a multi-pin DNS rebinding attack and
execute arbitrary JavaScript in an intranet context, when an intranet web server
has an HTML document that references a "mayscript=true" Java applet through a
local relative URI, which may be associated with different IP addresses by the
browser and the JVM.
Discussion:
This is from http://crypto.stanford.edu/dns/dns-rebinding.pdf, the two other bugs from this paper that were also identified alongside this bug were CVE-2007-5273 and CVE-2007-5274.
We queried Sun in June 2008 whether this is a duplicate of CVE-2007-5273 or CVE-2007-5274 . But we never received a
Bugzilla
CVE-2007-5274 Anti-DNS Pinning and Java Applets with Opera and Firefox
bugzilla·2007-10-09·CVSS 4.0
CVE-2007-5274 [MEDIUM] CVE-2007-5274 Anti-DNS Pinning and Java Applets with Opera and Firefox
CVE-2007-5274 Anti-DNS Pinning and Java Applets with Opera and Firefox
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and
earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15
and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or
Opera is used, allows remote attackers to violate the security model
for JavaScript outbound connections via a multi-pin DNS rebinding
attack dependent on the LiveConnect API, in which JavaScript download
relies on DNS resolution by the browser, but JavaScript socket
operations rely on separate DNS resolution by a Java Virtual Machine
(JVM), a different issue than CVE-2007-5273. NOTE: this is similar to
CVE-2007-5232, but affects different product versions.
Discussion:
The list of fixed products with their respective er
Bugzilla
CVE-2007-5273 Anti-DNS Pinning and Java Applets with HTTP proxy
bugzilla·2007-10-09·CVSS 4.0
CVE-2007-5273 [MEDIUM] CVE-2007-5273 Anti-DNS Pinning and Java Applets with HTTP proxy
CVE-2007-5273 Anti-DNS Pinning and Java Applets with HTTP proxy
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and
earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15
and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy
server is used, allows remote attackers to violate the security model
for an applet's outbound connections via a multi-pin DNS rebinding
attack in which the applet download relies on DNS resolution on the
proxy server, but the applet's socket operations rely on DNS
resolution on the local machine, a different issue than CVE-2007-5274.
NOTE: this is similar to CVE-2007-5232, but affects different product
versions.
Discussion:
The list of fixed products with their respective errata is here:
https://access.redhat.com/security
http://crypto.stanford.edu/dns/dns-rebinding.pdfhttp://dev2dev.bea.com/pub/advisory/272http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlhttp://osvdb.org/45527http://seclists.org/fulldisclosure/2007/Jul/0159.htmlhttp://secunia.com/advisories/27206http://secunia.com/advisories/27261http://secunia.com/advisories/27693http://secunia.com/advisories/27716http://secunia.com/advisories/27804http://secunia.com/advisories/28777http://secunia.com/advisories/28880http://secunia.com/advisories/29042http://secunia.com/advisories/29214http://secunia.com/advisories/29340http://secunia.com/advisories/29858http://secunia.com/advisories/29897http://secunia.com/advisories/30780http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://securitytracker.com/id?1018771http://sunsolve.sun.com/search/document.do?assetkey=1-26-103078-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200041-1http://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.novell.com/linux/security/advisories/2007_55_java.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0963.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1041.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0100.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0132.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0156.htmlhttp://www.securityfocus.com/archive/1/482926/100/0/threadedhttp://www.securityfocus.com/bid/25918http://www.vupen.com/english/advisories/2007/3895http://www.vupen.com/english/advisories/2008/0609https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10340http://crypto.stanford.edu/dns/dns-rebinding.pdfhttp://dev2dev.bea.com/pub/advisory/272http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlhttp://osvdb.org/45527http://seclists.org/fulldisclosure/2007/Jul/0159.htmlhttp://secunia.com/advisories/27206http://secunia.com/advisories/27261http://secunia.com/advisories/27693http://secunia.com/advisories/27716http://secunia.com/advisories/27804http://secunia.com/advisories/28777http://secunia.com/advisories/28880http://secunia.com/advisories/29042http://secunia.com/advisories/29214http://secunia.com/advisories/29340http://secunia.com/advisories/29858http://secunia.com/advisories/29897http://secunia.com/advisories/30780http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://securitytracker.com/id?1018771http://sunsolve.sun.com/search/document.do?assetkey=1-26-103078-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200041-1http://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.novell.com/linux/security/advisories/2007_55_java.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0963.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1041.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0100.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0132.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0156.htmlhttp://www.securityfocus.com/archive/1/482926/100/0/threadedhttp://www.securityfocus.com/bid/25918http://www.vupen.com/english/advisories/2007/3895http://www.vupen.com/english/advisories/2008/0609https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10340
2007-10-08
Published