This application requires Javascript for optimal performance.

Oracle.Java.Rhino.Script.Engine.Code.Execution

Release Date

Nov 30, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a Buffer Overflow vulnerability in
Oracle Java Runtime Environment.

It allows a remote attacker to execute arbitrary code via sending a crafted web page.

Affected Products

Oracle Java Runtime Environment version 6 update 27
Oracle Java Runtime Environment version 7

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-3544

Reference/s

http://www.securityfocus.com/bid/50218 (BugTraq)

Reference: VID-30202