CVE-2007-5375

Publication date 11 October 2007

Last updated 24 July 2024


Ubuntu priority

Interpretation conflict in the Sun Java Virtual Machine (JVM) allows user-assisted remote attackers to conduct a multi-pin DNS rebinding attack and execute arbitrary JavaScript in an intranet context, when an intranet web server has an HTML document that references a “mayscript=true” Java applet through a local relative URI, which may be associated with different IP addresses by the browser and the JVM.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
sun-java5 9.10 karmic Not in release
9.04 jaunty
Fixed 1.5.0-13-0ubuntu1
8.10 intrepid
Fixed 1.5.0-13-0ubuntu1
8.04 LTS hardy
Fixed 1.5.0-13-0ubuntu1
7.10 gutsy
Fixed 1.5.0-13-0ubuntu1
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life
sun-java6 9.10 karmic
Fixed 6-03-0ubuntu1
9.04 jaunty
Fixed 6-03-0ubuntu1
8.10 intrepid
Fixed 6-03-0ubuntu1
8.04 LTS hardy
Fixed 6-03-0ubuntu1
7.10 gutsy
Fixed 6-03-0ubuntu1
7.04 feisty Ignored end of life, was needed
6.10 edgy Not in release
6.06 LTS dapper Not in release