Update Protection against Sun Java GIF Image Remote Code Execution Vulnerability
| Check Point Reference: | CPAI-2007-063 | |
| Date Published: | ||
| Severity: | ||
| Source: | FrSIRT/ADV-2007-0211 | |
| Industry Reference(s): |
CVE-2007-0243 |
|
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Sun JDK version 5.0 Update 9 and prior Sun SDK version 1.4.2_12 and prior Sun SDK version 1.3.1_18 and prior Sun JRE version 5.0 Update 9 and prior Sun JRE version 1.4.2_12 and prior Sun JRE version 1.3.1_18 and prior | ||
| Vulnerability Description A remote code execution vulnerability exists in Sun Java Runtime Environment (JRE). The Sun Java Runtime Environment allows users to run Java applications in a browser or as standalone programs. A remote attacker can exploit this issue to take complete control over an affected system. |
||
|
Update/Patch Available Upgrade your vulnerable product: Java |
|
|
Vulnerability Details This vulnerability is due to a buffer overflow error in Sun JRE when processing malformed GIF files. An attacker can exploit this flaw via a malformed Java GIF file. Successful exploitation may allow the attacker to execute arbitrary code on a target system. |
Protection Overview
By enabling this protection, SmartDefense will detect and block malformed Java GIF files.
In order for the protection to be activated, update your VPN-1/InterSpect product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
The Update released on May 13, 2007 includes the following protections:
Apple Mac OS X GIF Image Vulnerability (CPAI-2007-059)
Mercury Mail Transport System Data Vulnerability (CPAI-2007-060)
Multiple Symantec SupportSoft ActiveX Control Vulnerabilities (CPAI-2007-061)
McAfee ePolicy Orchestrator SiteManager Multiple Vulnerabilities (CPAI-2007-062)
Sun Java GIF Image Vulnerability (CPAI-2007-063)