Back

HIGH

OpenJDK ImageI/O JPEG heap overflow (6874643)

Published Nov 5, 2009

Description

Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug Id 6874643.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (31)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 5, 2009
Updated Aug 7, 2024
Reserved Nov 5, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Nov 3, 2009