CVE-2007-6382
EPSS 0.82%Robocode Arbitrary Code Execution
發布日:2022/5/1修改日:2023/11/8
描述
The Event Dispatch Thread in Robocode before 1.5.1 allows remote attackers to execute arbitrary Java code by using a robot to invoke the `SwingUtilities.invokeLater` method.
受影響套件(1)
- Maven/net.sf.robocode:robocode.corefrom 0, < 1.5.1
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2007-6382
- PATCHhttps://github.com/robo-code/robocode
- WEBhttps://exchange.xforce.ibmcloud.com/vulnerabilities/39019
- WEBhttps://github.com/robo-code/robocode/blob/1abe65b65c34a8eb3d23de8f037dafae3c548fa5/versions.md?plain=1#L1880-L1887
- WEBhttps://github.com/robo-code/robocode/commit/2f2867d24fb28a2478983be57556f2355a774a81
- WEBhttps://github.com/robo-code/robocode/commit/8c6f5d77e7723583ba069ea611c33f22c1e9603a