MEDIUM
JDK DoS with crafted .jnlp file
Published Aug 10, 2009
5.0
MEDIUMCVSS 2.0
EPSS 2.03%
Description
The Java Web Start implementation in Sun Java SE 6 before Update 15 allows context-dependent attackers to cause a denial of service (NullPointerException) via a crafted .jnlp file, as demonstrated by the jnlp_file/appletDesc/index.html#misc test in the Technology Compatibility Kit (TCK) for the Java Network Launching Protocol (JNLP).
Affected products
No data.
No data.
Extras for RHEL 4
java-1.6.0-sun-1:1.6.0.15-1jpp.1.el4
Fixed · RHSA-2009:1200
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.15-1jpp.1.el5
Fixed · RHSA-2009:1200
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 4 | java-1.6.0-sun-1:1.6.0.15-1jpp.1.el4 | Fixed | RHSA-2009:1200 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.15-1jpp.1.el5 | Fixed | RHSA-2009:1200 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://java.sun.com/javase/6/webnotes/6u15.html x_refsource_CONFIRMVendor Advisory
- http://secunia.com/advisories/37386 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37460 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200911-02.xml vendor-advisoryx_refsource_GENTOO
- http://www.securityfocus.com/archive/1/507985/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.vmware.com/security/advisories/VMSA-2009-0016.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2009/3316 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-2719 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=516820 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-2719
- https://www.cve.org/CVERecord?id=CVE-2009-2719
| Link | Providers | Tags |
|---|---|---|
| http://java.sun.com/javase/6/webnotes/6u15.html | x_refsource_CONFIRMVendor Advisory | |
| http://secunia.com/advisories/37386 | third-party-advisoryx_refsource_SECUNIA | |
| http://secunia.com/advisories/37460 | third-party-advisoryx_refsource_SECUNIA | |
| http://security.gentoo.org/glsa/glsa-200911-02.xml | vendor-advisoryx_refsource_GENTOO | |
| http://www.securityfocus.com/archive/1/507985/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.vmware.com/security/advisories/VMSA-2009-0016.html | x_refsource_CONFIRM | |
| http://www.vupen.com/english/advisories/2009/3316 | vdb-entryx_refsource_VUPEN | |
| https://access.redhat.com/security/cve/CVE-2009-2719 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=516820 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-2719 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-2719 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 10, 2009
Updated Aug 7, 2024
Reserved Aug 10, 2009
Link CVE-2009-2719
CISA Vulnrichment
Updated n/a