OpenJDK resurrected classloaders can still have children (6636650)
Published Nov 9, 2009
7.5
HIGHCVSS 2.0
EPSS 2.67%
Description
Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gain privileges via unspecified vectors, related to an "information leak vulnerability," aka Bug Id 6636650.
Affected products
No data.
- ≤ 1.5.0
- ≤ 1.6.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- n/a
No data.
Extras for RHEL 4
java-1.5.0-sun-0:1.5.0.22-1jpp.1.el4
Fixed · RHSA-2009:1571
Extras for RHEL 4
java-1.6.0-sun-1:1.6.0.17-1jpp.1.el4
Fixed · RHSA-2009:1560
Red Hat Enterprise Linux 5
java-1.6.0-openjdk-1:1.6.0.0-1.7.b09.el5
Fixed · RHSA-2009:1584
Red Hat Network Satellite Server v 5.1
java-1.5.0-sun-0:1.5.0.22-1jpp.1.el4
Fixed · RHSA-2009:1662
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-sun-0:1.5.0.22-1jpp.1.el5
Fixed · RHSA-2009:1571
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.17-1jpp.2.el5
Fixed · RHSA-2009:1560
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 4 | java-1.5.0-sun-0:1.5.0.22-1jpp.1.el4 | Fixed | RHSA-2009:1571 |
| Extras for RHEL 4 | java-1.6.0-sun-1:1.6.0.17-1jpp.1.el4 | Fixed | RHSA-2009:1560 |
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk-1:1.6.0.0-1.7.b09.el5 | Fixed | RHSA-2009:1584 |
| Red Hat Network Satellite Server v 5.1 | java-1.5.0-sun-0:1.5.0.22-1jpp.1.el4 | Fixed | RHSA-2009:1662 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-sun-0:1.5.0.22-1jpp.1.el5 | Fixed | RHSA-2009:1571 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.17-1jpp.2.el5 | Fixed | RHSA-2009:1560 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- http://java.sun.com/j2se/1.5.0/ReleaseNotes.html x_refsource_CONFIRMVendor Advisory
- http://java.sun.com/javase/6/webnotes/6u17.html x_refsource_CONFIRMVendor Advisory
- http://secunia.com/advisories/37386 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200911-02.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:084 vendor-advisoryx_refsource_MANDRIVA
- https://access.redhat.com/security/cve/CVE-2009-3881 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=530173 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-3881
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11484 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6906 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-3881
| Link | Providers | Tags |
|---|---|---|
| http://java.sun.com/j2se/1.5.0/ReleaseNotes.html | x_refsource_CONFIRMVendor Advisory | |
| http://java.sun.com/javase/6/webnotes/6u17.html | x_refsource_CONFIRMVendor Advisory | |
| http://secunia.com/advisories/37386 | third-party-advisoryx_refsource_SECUNIA | |
| http://security.gentoo.org/glsa/glsa-200911-02.xml | vendor-advisoryx_refsource_GENTOO | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2010:084 | vendor-advisoryx_refsource_MANDRIVA | |
| https://access.redhat.com/security/cve/CVE-2009-3881 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=530173 | x_refsource_CONFIRMIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-3881 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11484 | vdb-entrysignaturex_refsource_OVAL | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6906 | vdb-entrysignaturex_refsource_OVAL | |
| https://www.cve.org/CVERecord?id=CVE-2009-3881 |
Change history (0)
No recorded changes yet.