CVE-2010-0842
published 2010-04-01CVE-2010-0842: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote…
PriorityP179high7.5CVSS 2.0
AVNACLAuNCPIPAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
77.72%
99.5th percentile
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an uncontrolled array index that allows remote attackers to execute arbitrary code via a MIDI file with a crafted MixerSequencer object, related to the GM_Song structure.
Affected
163 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.6.0 | — |
| sun | jdk | <= 1.5.0 | — |
| sun | jdk | <= 1.3.1_27 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect delivery of a crafted RMF file containing an embedded MIDI with a malicious controller event served over HTTP, identifiable by Content-Type 'application/octet-strem' (note the typo used by the exploit module). ↗
- →Monitor HTTP responses serving files with a .rmf extension, especially when followed by a .jar file request from the same browser session, as the exploit delivers both an RMF and a JAR payload. ↗
- →Alert on Java processes loading or playing RMF/MIDI files that trigger MixerSequencer object instantiation, particularly where EBX register is used as a jump target pointing into MIDI file data (shellcode stored in a fake MIDI event). ↗
- →The exploit uses a SONG block inside an RMF file to populate the GM_Song structure with an attacker-controlled function pointer; inspect RMF files for SONG blocks containing unexpected pointer-sized values. ↗
- →The exploit uses 'migrate -f' as an InitialAutoRunScript, meaning post-exploitation process migration will occur immediately; monitor for unexpected child process spawning from java.exe or javaw.exe shortly after RMF/MIDI file access. ↗
- ·The exploit targets Java 6 Update 18 and earlier (also 6u17 confirmed); the ROP gadget address 0x7C35A78D (jmp ebx in msvcr71.dll) is version-specific and may not apply to other Java or Windows configurations. ↗
- ·The exploit platform is Windows only; the jmp-ebx gadget from msvcr71.dll is a Windows-specific DLL and this technique does not apply to Linux/macOS Java deployments. ↗
- ·The Content-Type value used in the exploit ('application/octet-strem') contains a deliberate typo; detection rules matching the standard 'application/octet-stream' spelling will miss this specific exploit delivery. ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.5HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5mqp-g99f-6r5f: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5
ghsa_unreviewed·2022-05-02
CVE-2010-0842 [HIGH] GHSA-5mqp-g99f-6r5f: Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an uncontrolled array index that allows remote attackers to execute arbitrary code via a MIDI file with a crafted MixerSequencer object, related to the GM_Song structure.
VulnCheck
Oracle Java SE and Java for Business Sound Component Vulnerability
vulncheck·2010·CVSS 7.5
CVE-2010-0842 [HIGH] Oracle Java SE and Java for Business Sound Component Vulnerability
Oracle Java SE and Java for Business Sound Component Vulnerability
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an uncontrolled array index that allows remote attackers to execute arbitrary code via a MIDI file with a crafted MixerSequencer object, related to the GM_Song structure.
Affected: sun jre
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
VMware
Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
vendor_vmware·2011-02-10·CVSS 5.0
CVE-2008-0085 [MEDIUM] Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
VMSA-2011-0003: Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX VMware Security Advisory VMware Security Advisory Advisory ID: VMware Security Advisory Synopsis: Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX VMware Security Advisory Issue date: VMware Security Advisory Updated on: VMware Security Advisory CVE numbers:
CVEs: CVE-2008-0085, CVE-2008-0086, CVE-2008-0106, CVE-2008-0107, CVE-2008-3825, CVE-2008-5416, CVE-2009-1384, CVE-2009-2693, CVE-2009-2901, CVE-2009-2902, CVE-2009-3548, CVE-2009-3555, CVE-2009-4308, CVE-2010-0003, CVE-2010-0007, CVE-2010-0008, CVE-2010-0082, CVE-2010-0084, CVE-2010-0085,
Red Hat
kernel: sctp: do not reset the packet during sctp_packet_config
vendor_redhat·2010-09-15·CVSS 7.8
CVE-2010-3432 [HIGH] CWE-228 kernel: sctp: do not reset the packet during sctp_packet_config
kernel: sctp: do not reset the packet during sctp_packet_config
The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) via a certain sequence of SCTP traffic.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 3 as it did not include support for SCTP. This was addressed in Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2010-0958.html and https://rhn.redhat.com/errata/RHSA-2010-0842.html. Future updates in Red Hat Enterprise Linux 4 and 5 may address this flaw.
Mitigation: For users that do not run applications that use SCTP, y
Red Hat
JDK multiple unspecified vulnerabilities
vendor_redhat·2010-03-30·CVSS 7.5
CVE-2010-0842 [HIGH] JDK multiple unspecified vulnerabilities
JDK multiple unspecified vulnerabilities
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an uncontrolled array index that allows remote attackers to execute arbitrary code via a MIDI file with a crafted MixerSequencer object, related to the GM_Song structure.
No detection rules found.
Exploit-DB
Java MixerSequencer Object - GM_Song Structure Handling (Metasploit)
exploitdb·2012-02-16
CVE-2010-0842 Java MixerSequencer Object - GM_Song Structure Handling (Metasploit)
Java MixerSequencer Object - GM_Song Structure Handling (Metasploit)
---
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 "Java MixerSequencer Object GM_Song Structure Handling Vulnerability",
'Description' => %q{
This module exploits a flaw within the handling of MixerSequencer objects
in Java 6u18 and before.
Exploitation id done by supplying a specially crafted MIDI file within an RMF
File. When the MixerSequencer objects is used to play the file, the GM_Song
structure is populated with a function pointer provided by a SONG block in the
RMF.
Metasploit
Java MixerSequencer Object GM_Song Structure Handling Vulnerability
metasploit
Java MixerSequencer Object GM_Song Structure Handling Vulnerability
Java MixerSequencer Object GM_Song Structure Handling Vulnerability
This module exploits a flaw within the handling of MixerSequencer objects in Java 6u18 and before. Exploitation id done by supplying a specially crafted MIDI file within an RMF File. When the MixerSequencer objects is used to play the file, the GM_Song structure is populated with a function pointer provided by a SONG block in the RMF. A Midi block that contains a MIDI with a specially crafted controller event is used to trigger the vulnerability. When triggering the vulnerability "ebx" points to a fake event in the MIDI file which stores the shellcode. A "jmp ebx" from msvcr71.dll is used to make the exploit reliable over java updates.
Securelist
Investigation Report for the September 2014 Equation malware detection incident in the US
blogs_securelist·2017-11-16
Investigation Report for the September 2014 Equation malware detection incident in the US
Authors
- Kaspersky
## Background
In early October, a story was published by the Wall Street Journal alleging Kaspersky Lab software was used to siphon classified data from an NSA employee’s home computer system. Given that Kaspersky Lab has been at the forefront of fighting cyberespionage and cybercriminal activities on the Internet for over 20 years now, these allegations were treated very seriously. To assist any independent investigators and all the people who have been asking us questions whether those allegations were true, we decided to conduct an internal investigation to attempt to answer a few questions we had related to the article and some others that followed it:
1. Was our software used outside of its intended functionality to pull classified information from a person’s c
Securelist
Investigation Report for the September 2014 Equation malware detection incident in the US
blogs_securelist·2017-11-16
Investigation Report for the September 2014 Equation malware detection incident in the US
Authors
Kaspersky
## Background
In early October, a story was published by the Wall Street Journal alleging Kaspersky Lab software was used to siphon classified data from an NSA employee’s home computer system. Given that Kaspersky Lab has been at the forefront of fighting cyberespionage and cybercriminal activities on the Internet for over 20 years now, these allegations were treated very seriously. To assist any independent investigators and all the people who have been asking us questions whether those allegations were true, we decided to conduct an internal investigation to attempt to answer a few questions we had related to the article and some others that followed it:
Was our software used outside of its intended functionality to pull classified information from a person’s comput
Bugzilla
CVE-2010-3698 kvm: invalid selector in fs/gs causes kernel panic
bugzilla·2010-10-04·CVSS 4.9
CVE-2010-3698 [MEDIUM] CVE-2010-3698 kvm: invalid selector in fs/gs causes kernel panic
CVE-2010-3698 kvm: invalid selector in fs/gs causes kernel panic
Invoking ioctl(KVM_RUN) while having invalid selector in fs and/or gs register (via LDT modifications) forces kernel to panic (DoS).
Discussion:
Fixed in 2.6.36:
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=9581d442b9058d3699b4be568b6e5eae38a41493
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2010:0842 https://rhn.redhat.com/errata/RHSA-2010-0842.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2010:0842 https://rhn.redhat.com/errata/RHSA-2010-0842.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0898 https://rhn.redhat.com/errat
Bugzilla
CVE-2010-0839 CVE-2010-0842 CVE-2010-0843 CVE-2010-0844 JDK multiple unspecified vulnerabilities
bugzilla·2010-03-31·CVSS 7.5
CVE-2010-0839 [HIGH] CVE-2010-0839 CVE-2010-0842 CVE-2010-0843 CVE-2010-0844 JDK multiple unspecified vulnerabilities
CVE-2010-0839 CVE-2010-0842 CVE-2010-0843 CVE-2010-0844 JDK multiple unspecified vulnerabilities
Update 19 of Oracle/Sun Java fixes multiple unspecified vulnerabilities. (CVE-2010-0839, CVE-2010-0842, CVE-2010-0843, CVE-2010-0844)
Reference:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0337 https://rhn.redhat.com/errata/RHSA-2010-0337.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Supplementary for RHEL 5.2.z
Supplementary for RHEL 5.3.z
Via RHSA-2010:0338 https://rhn.redhat.com/errata/RHSA-2010-0338.html
---
This issue has been
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751http://lists.apple.com/archives/security-announce/2010//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010//May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://marc.info/?l=bugtraq&m=127557596201693&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/39317http://secunia.com/advisories/39659http://secunia.com/advisories/39819http://secunia.com/advisories/40211http://secunia.com/advisories/40545http://secunia.com/advisories/43308http://support.apple.com/kb/HT4170http://support.apple.com/kb/HT4171http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlhttp://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0337.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0338.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0383.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0471.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0489.htmlhttp://www.securityfocus.com/archive/1/510532/100/0/threadedhttp://www.securityfocus.com/archive/1/516397/100/0/threadedhttp://www.securityfocus.com/bid/39077http://www.vmware.com/security/advisories/VMSA-2011-0003.htmlhttp://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.htmlhttp://www.vupen.com/english/advisories/2010/1191http://www.vupen.com/english/advisories/2010/1454http://www.vupen.com/english/advisories/2010/1523http://www.vupen.com/english/advisories/2010/1793http://www.zerodayinitiative.com/advisories/ZDI-10-060https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14101http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751http://lists.apple.com/archives/security-announce/2010//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010//May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://marc.info/?l=bugtraq&m=127557596201693&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/39317http://secunia.com/advisories/39659http://secunia.com/advisories/39819http://secunia.com/advisories/40211http://secunia.com/advisories/40545http://secunia.com/advisories/43308http://support.apple.com/kb/HT4170http://support.apple.com/kb/HT4171http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlhttp://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0337.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0338.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0383.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0471.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0489.htmlhttp://www.securityfocus.com/archive/1/510532/100/0/threadedhttp://www.securityfocus.com/archive/1/516397/100/0/threadedhttp://www.securityfocus.com/bid/39077http://www.vmware.com/security/advisories/VMSA-2011-0003.htmlhttp://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.htmlhttp://www.vupen.com/english/advisories/2010/1191http://www.vupen.com/english/advisories/2010/1454http://www.vupen.com/english/advisories/2010/1523http://www.vupen.com/english/advisories/2010/1793http://www.zerodayinitiative.com/advisories/ZDI-10-060https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14101
2010-04-01
Published
Exploited in the wild