Skip to navigation

CVE Database

CVE-2010-4476

Impact: Moderate
Public: 2011-02-01
Bugzilla: 674336: CVE-2010-4476 JDK Double.parseDouble Denial-Of-Service
IAVA: 2011-A-0173

Details

The MITRE CVE dictionary describes this issue as:

The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.

Find out more about CVE-2010-4476 from the MITRE CVE dictionary and NIST NVD.

CVSS v2 metrics

Base Score: 5.0
Base Metrics: AV:N/AC:L/Au:N/C:N/I:N/A:P
Access Vector: Network
Access Complexity: Low
Authentication: None
Confidentiality Impact: None
Integrity Impact: None
Availability Impact: Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat security errata

Platform Errata Release Date
RHEL 4 AS for SAP (java-1.4.2-ibm-sap) RHSA-2011:0299 February 23, 2011
RHEL 5 Server for SAP (java-1.4.2-ibm-sap) RHSA-2011:0299 February 23, 2011
Red Hat Enterprise Linux Server Supplementary (v. 5) (java-1.4.2-ibm) RHSA-2011:0292 February 22, 2011
Red Hat Enterprise Linux Server Supplementary (v. 5) (java-1.5.0-ibm) RHSA-2011:0291 February 22, 2011
Red Hat Enterprise Linux Server Supplementary (v. 5) (java-1.6.0-ibm) RHSA-2011:0290 February 22, 2011
Red Hat Enterprise Linux Server Supplementary (v. 5) (java-1.6.0-sun) RHSA-2011:0282 February 17, 2011
Red Hat Enterprise Linux Supplementary version 6 (java-1.5.0-ibm) RHSA-2011:0291 February 22, 2011
Red Hat Enterprise Linux Supplementary version 6 (java-1.6.0-ibm) RHSA-2011:0290 February 22, 2011
Red Hat Enterprise Linux Supplementary version 6 (java-1.6.0-sun) RHSA-2011:0282 February 17, 2011
Red Hat Enterprise Linux version 4 Extras (java-1.4.2-ibm) RHSA-2011:0292 February 22, 2011
Red Hat Enterprise Linux version 4 Extras (java-1.5.0-ibm) RHSA-2011:0291 February 22, 2011
Red Hat Enterprise Linux version 4 Extras (java-1.6.0-ibm) RHSA-2011:0290 February 22, 2011
Red Hat Enterprise Linux version 4 Extras (java-1.6.0-sun) RHSA-2011:0282 February 17, 2011
Red Hat Enterprise Linux version 5 (java-1.6.0-openjdk) RHSA-2011:0214 February 11, 2011
Red Hat Enterprise Linux version 5 (tomcat5) RHSA-2011:0336 March 09, 2011
Red Hat Enterprise Linux version 6 (java-1.6.0-openjdk) RHSA-2011:0214 February 11, 2011
Red Hat Enterprise Linux version 6 (tomcat6) RHSA-2011:0335 March 09, 2011
Red Hat JBoss Enterprise Application Platform 4.2 RHSA-2011:0212 February 10, 2011
Red Hat JBoss Enterprise Application Platform 4.2.0 for RHEL 4 AS (jbossweb) RHSA-2011:0210 February 10, 2011
Red Hat JBoss Enterprise Application Platform 4.2.0 for RHEL 5 Server (jbossweb) RHSA-2011:0210 February 10, 2011
Red Hat JBoss Enterprise Application Platform 4.3 RHSA-2011:0212 February 10, 2011
Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 4 AS (jbossweb) RHSA-2011:0210 February 10, 2011
Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 5 Server (jbossweb) RHSA-2011:0210 February 10, 2011
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4 AS (jbossweb) RHSA-2011:0210 February 10, 2011
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server (jbossweb) RHSA-2011:0210 February 10, 2011
Red Hat JBoss Enterprise Application Platform 5.1 RHSA-2011:0212 February 10, 2011
Red Hat JBoss Portal 4.3 (jbossweb) RHSA-2011:0334 March 09, 2011
Red Hat JBoss Portal 5 (jbossweb) RHSA-2011:0334 March 09, 2011
Red Hat JBoss SOA Platform 4.3 (jbossweb) RHSA-2011:0333 March 09, 2011
Red Hat JBoss SOA Platform 5.0 (jbossweb) RHSA-2011:0333 March 09, 2011
Red Hat JBoss Web Platform 5 for RHEL 4 AS (jbossweb) RHSA-2011:0211 February 10, 2011
Red Hat JBoss Web Platform 5 for RHEL 5 Server (jbossweb) RHSA-2011:0211 February 10, 2011
Red Hat JBoss Web Platform 5.1 RHSA-2011:0213 February 10, 2011
Red Hat JBoss Web Server 1.0 (tomcat) RHSA-2011:0350 March 11, 2011
Red Hat JBoss Web Server 1.0 for RHEL 4 AS (tomcat5) RHSA-2011:0349 March 11, 2011
Red Hat JBoss Web Server 1.0 for RHEL 4 AS (tomcat6) RHSA-2011:0348 March 11, 2011
Red Hat JBoss Web Server 1.0 for RHEL 5 Server (tomcat5) RHSA-2011:0349 March 11, 2011
Red Hat JBoss Web Server 1.0 for RHEL 5 Server (tomcat6) RHSA-2011:0348 March 11, 2011
Red Hat Satellite 5.4 (RHEL v.5) (java-1.6.0-ibm) RHSA-2011:0880 June 16, 2011

External References

This page is generated automatically and has not been checked for errors or omissions.

For clarification or corrections please contact the Red Hat Security Response Team.