Vulnerability Name:

CVE-2010-0843 (CCN-57357)

Assigned:2010-03-30
Published:2010-03-30
Updated:2018-10-10
Summary:Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Note: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to XNewPtr and improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, which allows remote attackers to execute arbitrary code.
Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE:

• JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux


• JDK 5.0 Update 23 and earlier for Solaris


• SDK 1.4.2_25 and earlier for Solaris

• Java for Business:

• JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux


• JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux


• SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (REDHAT CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2010-0843

Source: CCN
Type: HP Security Bulletin HPSBMA02547 SSRT100196
HP Systems Insight Manager (SIM) for HP-UX, Linux, and Windows, Remote Execution of Arbitrary Code and Other Vulnerabilities

Source: HP
Type: UNKNOWN
SSRT100179

Source: APPLE
Type: UNKNOWN
APPLE-SA-2010-05-18-1

Source: APPLE
Type: UNKNOWN
APPLE-SA-2010-05-18-2

Source: SUSE
Type: UNKNOWN
SUSE-SR:2010:008

Source: SUSE
Type: UNKNOWN
SUSE-SR:2010:017

Source: HP
Type: UNKNOWN
SSRT100089

Source: HP
Type: UNKNOWN
HPSBMU02799

Source: OSVDB
Type: UNKNOWN
63492

Source: CCN
Type: RHSA-2010-0337
Critical: java-1.6.0-sun security update

Source: CCN
Type: RHSA-2010-0338
Critical: java-1.5.0-sun security update

Source: CCN
Type: RHSA-2010-0383
Critical: java-1.6.0-ibm security update

Source: CCN
Type: RHSA-2010-0471
Low: Red Hat Network Satellite Server IBM Java Runtime security update

Source: CCN
Type: RHSA-2010-0489
Critical: java-1.5.0-ibm security update

Source: CCN
Type: RHSA-2010-0574
Critical: java-1.4.2-ibm security update

Source: CCN
Type: RHSA-2010-0586
Moderate: java-1.4.2-ibm-sap security update

Source: BUGTRAQ
Type: UNKNOWN
20100405 ZDI-10-052: Sun Java Runtime Environment XNewPtr Remote Code Execution Vulnerability

Source: CCN
Type: SA37255
Sun Java JDK / JRE Multiple Vulnerabilities

Source: CCN
Type: SA39317
SUSE Update for Multiple Packages

Source: SECUNIA
Type: Vendor Advisory
39317

Source: SECUNIA
Type: Vendor Advisory
39659

Source: CCN
Type: SA39819
Apple Mac OS X update for Java

Source: SECUNIA
Type: Vendor Advisory
39819

Source: CCN
Type: SA40057
IBM Java Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
40211

Source: CCN
Type: SA40545
HP Systems Insight Manager Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
40545

Source: CCN
Type: SA40772
IBM Java Multiple Vulnerabilities

Source: CCN
Type: SA43308
VMware vCenter / ESX Server Update for Oracle (Sun) JRE

Source: SECUNIA
Type: Vendor Advisory
43308

Source: CONFIRM
Type: UNKNOWN
http://support.apple.com/kb/HT4170

Source: CONFIRM
Type: UNKNOWN
http://support.apple.com/kb/HT4171

Source: CCN
Type: IBM Security alerts
Oracle Synchronized Security Releases (SSR)

Source: CCN
Type: IBM Web site
developerWorks : Java; technology : IBM developer kits : Additional documentation

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html

Source: CCN
Type: Oracle Critical Patch Update Advisory - March 2010
Oracle Java SE and Java for Business Critical Patch Update Advisory - March 2022

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html

Source: CCN
Type: OSVDB ID: 63492
Oracle Java SE / Java for Business com.sun.media.sound Library Unspecified Function Remote Code Execution

Source: REDHAT
Type: UNKNOWN
RHSA-2010:0337

Source: REDHAT
Type: UNKNOWN
RHSA-2010:0338

Source: REDHAT
Type: UNKNOWN
RHSA-2010:0383

Source: REDHAT
Type: UNKNOWN
RHSA-2010:0471

Source: REDHAT
Type: UNKNOWN
RHSA-2010:0489

Source: BUGTRAQ
Type: UNKNOWN
20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX

Source: BID
Type: UNKNOWN
39083

Source: CCN
Type: BID-39083
Oracle Java SE and Java for Business 'XNewPtr()' Remote Code Execution Vulnerability

Source: CONFIRM
Type: UNKNOWN
http://www.vmware.com/security/advisories/VMSA-2011-0003.html

Source: CONFIRM
Type: UNKNOWN
http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html

Source: VUPEN
Type: Vendor Advisory
ADV-2010-1191

Source: VUPEN
Type: Vendor Advisory
ADV-2010-1454

Source: VUPEN
Type: Vendor Advisory
ADV-2010-1523

Source: VUPEN
Type: Vendor Advisory
ADV-2010-1793

Source: MISC
Type: UNKNOWN
http://www.zerodayinitiative.com/advisories/ZDI-10-052/

Source: XF
Type: UNKNOWN
javase-javab-bs-unspecified-var2(57357)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:14092

Source: SUSE
Type: SUSE-SA:2010:026
IBM Java 6 security update

Source: SUSE
Type: SUSE-SA:2010:028
IBM Java 5 update

Source: SUSE
Type: SUSE-SR:2010:008
SUSE Security Summary Report

Source: SUSE
Type: SUSE-SR:2010:017
(java-1_4_2-ibm, sudo, libpng, php5, tgt, iscsitarget, aria2, pcsc-lite, tomcat5, tomcat6, lvm2, libvirt, rpm, libtiff, dovecot12)

Source: CCN
Type: ZDI-10-052
Sun Java Runtime Environment XNewPtr Remote Code Execution Vulnerability

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sun:jdk:1.5.0:update23:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.6.0:update_18:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_27:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.4.2_25:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.5.0:update23:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.6.0:update_18:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_27:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.4.2_25:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:rhel_extras:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:rhel_extras:5:*:*:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/a:redhat:rhel_extras:4.7.z:*:*:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/a:redhat:rhel_extras:3:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:hp:systems_insight_manager:4.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.1:sp1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.2:sp1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.2:sp2:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp2:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp3:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp4:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp5:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:-:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.1:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.2:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.2:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.4.2_25:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_27:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.3:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.3:update_1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:6.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:redhat:rhel_extras:3:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:rhel_extras:4:*:*:*:*:*:*:*
  • OR cpe:/o:novell:suse_linux_enterprise_server:10:sp2:itanium_ia64:*:*:*:*:*
  • OR cpe:/a:novell:open_enterprise_server:*:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:java:1.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:java:5.0.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:java:6.0.0.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20100843
    V
    CVE-2010-0843
    2022-05-20
    oval:org.opensuse.security:def:42127
    P
    Security update for glibc (Moderate)
    2021-10-12
    oval:org.opensuse.security:def:31274
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-09-23
    oval:org.opensuse.security:def:31642
    P
    Security update for webkit2gtk3 (Important)
    2021-06-17
    oval:org.opensuse.security:def:31200
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-15
    oval:org.opensuse.security:def:31188
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:31189
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:26047
    P
    Security update for xen (Important)
    2021-05-12
    oval:org.opensuse.security:def:32008
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP3) (Important)
    2020-12-07
    oval:org.opensuse.security:def:35720
    P
    java-1_4_2-ibm-1.4.2_sr13.10-0.4.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25283
    P
    Security update for SUSE Manager Client Tools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32646
    P
    curl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25989
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25475
    P
    Security update for libssh (Important)
    2020-12-01
    oval:org.opensuse.security:def:31854
    P
    Security update for cracklib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25613
    P
    Security update for libsolv (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26720
    P
    java-1_4_2-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31942
    P
    Security update for gnome-session (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25848
    P
    Security update for flex, at, bogofilter, cyrus-imapd, kdelibs4, libQtWebKit4, libbonobo, mdbtools, netpbm, openslp, sgmltool, virtuoso, libqt5-qtwebkit (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31406
    P
    Security update for perl-PlRPC (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25272
    P
    Security update for vino (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25950
    P
    Security update for evince (Important)
    2020-12-01
    oval:org.opensuse.security:def:31555
    P
    Security update for sqlite3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25347
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32685
    P
    java-1_4_2-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26003
    P
    Security update for yaml-cpp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31798
    P
    Security update for OpenEXR (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25556
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26685
    P
    dhcp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31903
    P
    Security update for fontconfig (Low)
    2020-12-01
    oval:org.opensuse.security:def:25697
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25271
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31964
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25901
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:31498
    P
    Security update for python-numpy (Important)
    2020-12-01
    oval:org.mitre.oval:def:14092
    V
    Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to XNewPtr and improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, which allows remote attackers to execute arbitrary code.
    2015-03-23
    oval:org.mitre.oval:def:23097
    P
    ELSA-2010:0338: java-1.5.0-sun security update (Critical)
    2014-05-26
    oval:org.mitre.oval:def:22564
    P
    ELSA-2010:0383: java-1.6.0-ibm security update (Critical)
    2014-05-26
    oval:org.mitre.oval:def:23141
    P
    ELSA-2010:0489: java-1.5.0-ibm security update (Critical)
    2014-05-26
    oval:org.mitre.oval:def:22706
    P
    ELSA-2010:0574: java-1.4.2-ibm security update (Critical)
    2014-05-26
    oval:org.mitre.oval:def:22952
    P
    ELSA-2010:0337: java-1.6.0-sun security update (Critical)
    2014-05-26
    oval:org.mitre.oval:def:22088
    P
    RHSA-2010:0337: java-1.6.0-sun security update (Critical)
    2014-02-24
    oval:org.mitre.oval:def:22101
    P
    RHSA-2010:0338: java-1.5.0-sun security update (Critical)
    2014-02-24
    oval:org.mitre.oval:def:22249
    P
    RHSA-2010:0489: java-1.5.0-ibm security update (Critical)
    2014-02-24
    oval:org.mitre.oval:def:21415
    P
    RHSA-2010:0383: java-1.6.0-ibm security update (Critical)
    2014-02-24
    oval:org.mitre.oval:def:22358
    P
    RHSA-2010:0574: java-1.4.2-ibm security update (Critical)
    2014-02-24
    oval:com.redhat.rhsa:def:20100574
    P
    RHSA-2010:0574: java-1.4.2-ibm security update (Critical)
    2010-07-29
    oval:com.redhat.rhsa:def:20100489
    P
    RHSA-2010:0489: java-1.5.0-ibm security update (Critical)
    2010-06-17
    oval:com.redhat.rhsa:def:20100383
    P
    RHSA-2010:0383: java-1.6.0-ibm security update (Critical)
    2010-04-29
    oval:com.redhat.rhsa:def:20100337
    P
    RHSA-2010:0337: java-1.6.0-sun security update (Critical)
    2010-03-31
    oval:com.redhat.rhsa:def:20100338
    P
    RHSA-2010:0338: java-1.5.0-sun security update (Critical)
    2010-03-31
    BACK
    sun jdk 1.5.0 update23
    sun jdk 1.6.0 update_18
    sun jre 1.3.1_27
    sun jre 1.4.2_25
    sun jre 1.5.0 update23
    sun jre 1.6.0 update_18
    sun sdk 1.3.1_27
    sun sdk 1.4.2_25
    hp systems insight manager 4.0 sp1
    hp systems insight manager 4.1 sp1
    hp systems insight manager 4.2 sp1
    hp systems insight manager 4.2 sp2
    hp systems insight manager 5.0 sp1
    hp systems insight manager 5.0 sp2
    hp systems insight manager 5.0 sp3
    hp systems insight manager 5.0 sp4
    hp systems insight manager 5.0 sp5
    hp systems insight manager -
    hp systems insight manager 4.0
    hp systems insight manager 4.1
    hp systems insight manager 4.2
    hp systems insight manager 5.0
    hp systems insight manager 5.2
    sun sdk 1.4.2_25
    sun sdk 1.3.1_27
    hp systems insight manager 5.3
    hp systems insight manager 5.3 update_1
    hp systems insight manager 6.0
    redhat rhel extras 3
    redhat rhel extras 4
    novell suse linux enterprise server 10 sp2
    novell open enterprise server *
    ibm java 1.4.2
    ibm java 5.0.0.0
    ibm java 6.0.0.0