Lucene search

K
cve[email protected]CVE-2011-0311
HistorySep 02, 2011 - 11:55 p.m.

CVE-2011-0311

2011-09-0223:55:01
CWE-119
web.nvd.nist.gov
26
ibm
java
technology
denial of service
vulnerability
cve-2011-0311

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:N/A:P

6.3 Medium

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

86.9%

The class file parser in IBM Java before 1.4.2 SR13 FP9, as used in IBM Runtimes for Java Technology 5.0.0 before SR13 and 6.0.0 before SR10, allows remote authenticated users to cause a denial of service (JVM segmentation fault, and possibly memory consumption or an infinite loop) via a crafted attribute length field in a class file, which triggers a buffer over-read.

Affected configurations

NVD
Node
ibmjavaRange1.4.2.13.8
OR
ibmjavaMatch1.4.2
OR
ibmjavaMatch1.4.2.13
OR
ibmjavaMatch1.4.2.13.1
OR
ibmjavaMatch1.4.2.13.2
OR
ibmjavaMatch1.4.2.13.3
OR
ibmjavaMatch1.4.2.13.4
OR
ibmjavaMatch1.4.2.13.5
OR
ibmjavaMatch1.4.2.13.6
OR
ibmjavaMatch1.4.2.13.7
OR
ibmruntimes_for_java_technologyRange5.0.12.4
OR
ibmruntimes_for_java_technologyRange6.0.9.0
OR
ibmruntimes_for_java_technologyMatch5.0.0
OR
ibmruntimes_for_java_technologyMatch5.0.11.0
OR
ibmruntimes_for_java_technologyMatch5.0.11.1
OR
ibmruntimes_for_java_technologyMatch5.0.11.2
OR
ibmruntimes_for_java_technologyMatch5.0.12.0
OR
ibmruntimes_for_java_technologyMatch5.0.12.1
OR
ibmruntimes_for_java_technologyMatch5.0.12.2
OR
ibmruntimes_for_java_technologyMatch5.0.12.3
OR
ibmruntimes_for_java_technologyMatch6.0.0
OR
ibmruntimes_for_java_technologyMatch6.0.1.0
OR
ibmruntimes_for_java_technologyMatch6.0.2.0
OR
ibmruntimes_for_java_technologyMatch6.0.3.0
OR
ibmruntimes_for_java_technologyMatch6.0.4.0
OR
ibmruntimes_for_java_technologyMatch6.0.5.0
OR
ibmruntimes_for_java_technologyMatch6.0.6.0
OR
ibmruntimes_for_java_technologyMatch6.0.7.0
OR
ibmruntimes_for_java_technologyMatch6.0.8.0
OR
ibmruntimes_for_java_technologyMatch6.0.8.1

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:N/A:P

6.3 Medium

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

86.9%