Heap-based Buffer Overflow in Sun Java System Web Server
CVE-2010-0387

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
25 January 2010

Summary

The Sun Java System Web Server 7.0 Update 7 is susceptible to multiple heap-based buffer overflows in both webservd and its administrative server. An attacker can exploit this vulnerability by sending a specially crafted long string within an 'Authorization: Digest' HTTP header, possibly leading to a denial of service by crashing the daemon and potentially allowing for additional exploits, although the exact impact may remain unspecified.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.