Java Web Start Buffer JPEG processing integer overflow (6823373)
Published Aug 5, 2009
7.5
HIGHCVSS 2.0
EPSS 6.39%
Description
Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during display to a splash screen, which triggers a heap-based buffer overflow.
Affected products
No data.
- 1.6.0
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
- 6
No data.
Extras for RHEL 4
java-1.6.0-ibm-1:1.6.0.6-1jpp.3.el4
Fixed · RHSA-2009:1582
Extras for RHEL 4
java-1.6.0-sun-1:1.6.0.15-1jpp.1.el4
Fixed · RHSA-2009:1200
Red Hat Enterprise Linux 5
java-1.6.0-openjdk-1:1.6.0.0-1.2.b09.el5
Fixed · RHSA-2009:1201
Red Hat Network Satellite Server v 5.3
java-1.6.0-ibm-1:1.6.0.7-1jpp.2.el5
Fixed · RHSA-2010:0043
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-ibm-1:1.6.0.6-1jpp.3.el5
Fixed · RHSA-2009:1582
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.15-1jpp.1.el5
Fixed · RHSA-2009:1200
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 4 | java-1.6.0-ibm-1:1.6.0.6-1jpp.3.el4 | Fixed | RHSA-2009:1582 |
| Extras for RHEL 4 | java-1.6.0-sun-1:1.6.0.15-1jpp.1.el4 | Fixed | RHSA-2009:1200 |
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk-1:1.6.0.0-1.2.b09.el5 | Fixed | RHSA-2009:1201 |
| Red Hat Network Satellite Server v 5.3 | java-1.6.0-ibm-1:1.6.0.7-1jpp.2.el5 | Fixed | RHSA-2010:0043 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-ibm-1:1.6.0.6-1jpp.3.el5 | Fixed | RHSA-2009:1582 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.15-1jpp.1.el5 | Fixed | RHSA-2009:1200 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (30)
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=125787273209737&w=2 vendor-advisoryx_refsource_HP
- http://secunia.com/advisories/36162 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36176 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36180 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36248 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/37300 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/37386 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://security.gentoo.org/glsa/glsa-200911-02.xml vendor-advisoryx_refsource_GENTOO
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1 x_refsource_CONFIRMPatch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-263428-1 vendor-advisoryx_refsource_SUNALERTPatchVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:209 vendor-advisoryx_refsource_MANDRIVA
- http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html x_refsource_CONFIRM
- http://www.us-cert.gov/cas/techalerts/TA09-294A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2009/2543 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-09-050/ x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2009-2674 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=512915 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52339 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-2674
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10073 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8073 vdb-entrysignaturex_refsource_OVAL
- https://rhn.redhat.com/errata/RHSA-2009-1200.html vendor-advisoryx_refsource_REDHAT
- https://rhn.redhat.com/errata/RHSA-2009-1201.html vendor-advisoryx_refsource_REDHAT
- https://www.cve.org/CVERecord?id=CVE-2009-2674
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.