HTTP: Oracle Java MixerSequencer.nAddControllerEventCallback Array Overflow

This signature detects attempts to exploit a known flaw in Java. A code execution vulnerability exists in Oracle's JDK and JRE. The vulnerability is due to improper boundary check and using an out-of-bounds array index. A remote, unauthenticated attacker could exploit this vulnerability by enticing a target user to open a Java applet or application via a web page (or other means). Successful exploitation could lead to arbitrary code execution in the target user's security context.

Extended Description

Oracle Java SE is prone to a remote vulnerability in Java Runtime Environment. The vulnerability can be exploited over multiple protocols. This issue affects the 'Sound' sub-component. This vulnerability affects the following supported versions: 6 Update 27, 5.0 Update 31, 1.4.2_33, JRockit R28.1.4

Affected Products

Xerox freeflow_print_server_(ffps),Sun jre_(linux_production_release)

References

BugTraq: 50220

CVE: CVE-2011-3545

Short Name
HTTP:STC:JAVA:MIXERSEQ-OF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Array CVE-2011-3545 Java MixerSequencer.nAddControllerEventCallback Oracle Overflow bid:50220
Release Date
11/29/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
False Positive
Unknown
Vendors

Red_hat

Suse

Apple

Gentoo

Sun

Hp

Avaya

Xerox

Hitachi

Oracle

Panda

Vmware

Ibm

CVSS Score

10.0

Found a potential security threat?