Bug 321991 (CVE-2007-5240) - CVE-2007-5240 Applets or Applications are allowed to display an oversized window
Summary: CVE-2007-5240 Applets or Applications are allowed to display an oversized window
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2007-5240
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 322031 322041 368071 368081 368091 368111 368121 435710 435711 435895 435896 435897 455573
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-10-07 12:12 UTC by Marc Schoenefeld
Modified: 2019-09-29 12:21 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-06-10 20:28:26 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2007:0963 0 normal SHIPPED_LIVE Important: java-1.5.0-sun security update 2007-10-12 09:55:14 UTC
Red Hat Product Errata RHSA-2007:1041 0 normal SHIPPED_LIVE Important: java-1.5.0-ibm security update 2007-11-26 16:37:14 UTC
Red Hat Product Errata RHSA-2008:0100 0 normal SHIPPED_LIVE Moderate: java-1.4.2-bea security update 2008-03-11 14:09:38 UTC
Red Hat Product Errata RHSA-2008:0132 0 normal SHIPPED_LIVE Critical: java-1.4.2-ibm security update 2008-02-14 14:46:54 UTC
Red Hat Product Errata RHSA-2008:0156 0 normal SHIPPED_LIVE Moderate: java-1.5.0-bea security update 2008-03-05 10:41:57 UTC

Description Marc Schoenefeld 2007-10-07 12:12:24 UTC
Sun describes a flaw at: 

http://sunsolve.sun.com/search/document.do?assetkey=1-26-103071-1

When an untrusted applet or application displays a window, the Java Runtime
Environment includes a warning banner inside the window to indicate that the
applet or application is untrusted. A defect in the Java Runtime Environment may
allow an untrusted applet or application that is downloaded from a malicious
website to display a window that exceeds the size of a user's screen so that the
warning banner is not visible to the user.


Note You need to log in before you can comment on or make changes to this bug.