CVE-2010-3559

N/A Unknown
Published: October 19, 2010 Modified: April 29, 2026
View on NVD

Description

Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this involves an incorrect sign extension in the HeadspaceSoundbank.nGetName function, which allows attackers to execute arbitrary code via a crafted BANK record that leads to a buffer overflow.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/41967
Source: secalert_us@oracle.com
http://secunia.com/advisories/42974
Source: secalert_us@oracle.com
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Source: secalert_us@oracle.com
Patch Vendor Advisory
http://www.securityfocus.com/bid/44026
Source: secalert_us@oracle.com
http://marc.info/?l=bugtraq&m=134254866602253&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/41967
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/42974
Source: af854a3a-2127-422b-91ae-364da2661108
http://support.avaya.com/css/P8/documents/100114315
Source: af854a3a-2127-422b-91ae-364da2661108
http://support.avaya.com/css/P8/documents/100123193
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0770.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2010-0807.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2010-0873.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/516397/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/44026
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vmware.com/security/advisories/VMSA-2011-0003.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.zerodayinitiative.com/advisories/ZDI-10-208/
Source: af854a3a-2127-422b-91ae-364da2661108

36 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
9.7%
95th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

sun