CVE-2009-2674
Java Web Start Buffer JPEG processing integer overflow (6823373)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during display to a splash screen, which triggers a heap-based buffer overflow.
Un desbordamiento de enteros en el archivo javaws.exe en Sun Java Web Start en Sun Java Runtime Environment (JRE) en JDK y JRE versión 6 anterior a Update 15, permite a los atacantes dependiendo del contexto ejecutar código arbitrario por medio de una imagen JPEG creada que no se maneja apropiadamente durante la visualización de una imagen de bienvenida, que desencadena un desbordamiento de búfer basado en la región heap de la memoria.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-08-05 CVE Reserved
- 2009-08-05 CVE Published
- 2023-05-11 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-190: Integer Overflow or Wraparound
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (28)
URL | Tag | Source |
---|---|---|
http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html | X_refsource_confirm | |
http://www.us-cert.gov/cas/techalerts/TA09-294A.html | Third Party Advisory | |
http://www.zerodayinitiative.com/advisories/ZDI-09-050 | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/52339 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10073 | Signature | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8073 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1 | 2018-10-30 | |
http://sunsolve.sun.com/search/document.do?assetkey=1-66-263428-1 | 2018-10-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 1.6.0 Search vendor "Sun" for product "Jdk" and version "1.6.0" | update2 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 6 Search vendor "Sun" for product "Jdk" and version "6" | update_1 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 6 Search vendor "Sun" for product "Jdk" and version "6" | update_10 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 6 Search vendor "Sun" for product "Jdk" and version "6" | update_11 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 6 Search vendor "Sun" for product "Jdk" and version "6" | update_12 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 6 Search vendor "Sun" for product "Jdk" and version "6" | update_13 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 6 Search vendor "Sun" for product "Jdk" and version "6" | update_2 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 6 Search vendor "Sun" for product "Jdk" and version "6" | update_3 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 6 Search vendor "Sun" for product "Jdk" and version "6" | update_4 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 6 Search vendor "Sun" for product "Jdk" and version "6" | update_5 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 6 Search vendor "Sun" for product "Jdk" and version "6" | update_6 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 6 Search vendor "Sun" for product "Jdk" and version "6" | update_7 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 6 Search vendor "Sun" for product "Jdk" and version "6" | update_8 |
Affected
| ||||||
Sun Search vendor "Sun" | Jdk Search vendor "Sun" for product "Jdk" | 6 Search vendor "Sun" for product "Jdk" and version "6" | update_9 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 6 Search vendor "Sun" for product "Jre" and version "6" | update_1 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 6 Search vendor "Sun" for product "Jre" and version "6" | update_10 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 6 Search vendor "Sun" for product "Jre" and version "6" | update_11 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 6 Search vendor "Sun" for product "Jre" and version "6" | update_12 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 6 Search vendor "Sun" for product "Jre" and version "6" | update_13 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 6 Search vendor "Sun" for product "Jre" and version "6" | update_2 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 6 Search vendor "Sun" for product "Jre" and version "6" | update_3 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 6 Search vendor "Sun" for product "Jre" and version "6" | update_4 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 6 Search vendor "Sun" for product "Jre" and version "6" | update_5 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 6 Search vendor "Sun" for product "Jre" and version "6" | update_6 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 6 Search vendor "Sun" for product "Jre" and version "6" | update_7 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 6 Search vendor "Sun" for product "Jre" and version "6" | update_8 |
Affected
| ||||||
Sun Search vendor "Sun" | Jre Search vendor "Sun" for product "Jre" | 6 Search vendor "Sun" for product "Jre" and version "6" | update_9 |
Affected
|