Vulnerability Name:

CVE-2003-1572 (CCN-12020)

Assigned:2003-05-14
Published:2003-05-14
Updated:2009-06-02
Summary:Sun Java Media Framework (JMF) 2.1.1 through 2.1.1c allows unsigned applets to cause a denial of service (JVM crash) and read or write unauthorized memory locations via the ReadEnv class, as demonstrated by reading environment variables using modified .data and .size fields.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Access
References:Source: BUGTRAQ
Type: UNKNOWN
20030625 Privilege escalation applet, Java Media Framework

Source: CCN
Type: BugTraq Mailing List, Tue Jun 24 2003 - 18:10:03 CDT
Privilege escalation applet, Java Media Framework

Source: MITRE
Type: CNA
CVE-2003-1572

Source: CCN
Type: JMF Web site
JMF Home Page

Source: CCN
Type: SECTRACK ID: 1006777
Java Media Framework Bug May Let Remote Applets Crash the Java Virtual Machine or Gain Unauthorized Privileges

Source: SECTRACK
Type: UNKNOWN
1006777

Source: SUNALERT
Type: UNKNOWN
54760

Source: CCN
Type: Sun Alert ID: 54760
Java Virtual Machine (JVM) May Crash Due to Vulnerability in the Java Media Framework (JMF)

Source: MISC
Type: UNKNOWN
http://www.illegalaccess.org/java/jmf.php

Source: CCN
Type: OSVDB ID: 2213
Java Media Framework Unsigned Applet Privilege Escalation

Source: CCN
Type: BID-7612
Sun Java Media Framework Unspecified Denial of Service Vulnerability

Source: XF
Type: UNKNOWN
jrm-jvm-unauth-privileges(12020)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sun:jmf:2.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jmf:2.1.1a:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jmf:2.1.1b:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jmf:2.1.1c:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sun jmf 2.1.1
    sun jmf 2.1.1a
    sun jmf 2.1.1b
    sun jmf 2.1.1c