Sun Java JRE 1.1.x through 1.4.x writes temporary files with long filenames that become predictable on a file system that uses 8.3 style short names, which allows remote attackers to write arbitrary files to known locations and facilitates the exploitation of vulnerabilities in applications that rely on unpredictable file names.
References
Link | Resource |
---|---|
http://secunia.com/advisories/11070/ | Vendor Advisory |
http://secunia.com/secunia_research/2004-7/advisory/ | |
http://www.kb.cert.org/vuls/id/544392 | Third Party Advisory US Government Resource |
https://exchange.xforce.ibmcloud.com/vulnerabilities/19285 | |
http://secunia.com/advisories/11070/ | Vendor Advisory |
http://secunia.com/secunia_research/2004-7/advisory/ | |
http://www.kb.cert.org/vuls/id/544392 | Third Party Advisory US Government Resource |
https://exchange.xforce.ibmcloud.com/vulnerabilities/19285 |
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:55
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/11070/ - Vendor Advisory | |
References | () http://secunia.com/secunia_research/2004-7/advisory/ - | |
References | () http://www.kb.cert.org/vuls/id/544392 - Third Party Advisory, US Government Resource | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/19285 - |
Information
Published : 2005-03-14 05:00
Updated : 2024-11-20 23:55
NVD link : CVE-2005-0471
Mitre link : CVE-2005-0471
CVE.ORG link : CVE-2005-0471
JSON object : View
Products Affected
sun
- jre
- jdk
CWE