4.6
CVSSv2

CVE-2003-1156

Published: 31/12/2003 Updated: 11/07/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 up to and including 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.

Vulnerable Product Search on Vulmon Subscribe to Product

sun jre 1.4.2

sun jdk 1.4.2

sun jdk 1.4.2_02