// For flags

CVE-2009-2675

Sun Java Pack200 Decoding Inner Class Count Integer Overflow Vulnerability

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.

Un desbordamiento de enteros en la utilidad unpack200 en Sun Java Runtime Environment (JRE) en JDK y JRE versión 6 anterior a Update 15, y JDK y JRE versión 5.0 anterior a Update 20, permite a los atacantes dependiendo del contexto alcanzar privilegios por medio de campos de longitud no especificados en el encabezado de un archivo JAR comprimido de Pack200-, que conlleva a un desbordamiento del búfer en la región heap de la memoria durante la descompresión.

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the Sun Java Runtime. User interaction is required in that a target must visit a malicious web page or open a malicious JNLP file.
The specific flaw exists within the code responsible for handling Pack200 compressed JAR files. During decompression, several fields within a Pack200 header are trusted and used to calculate sizes for heap buffer allocations. By providing malicious values an attacker can create undersized heap buffers and subsequently overflow them. This can be leveraged to execute arbitrary code under the context of the user accessing the file or web page.

*Credits: Anonymous
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-08-05 CVE Reserved
  • 2009-08-05 CVE Published
  • 2023-11-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-190: Integer Overflow or Wraparound
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (35)
URL Date SRC
URL Date SRC
http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html 2018-10-10
http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.html 2018-10-10
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html 2018-10-10
http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.html 2018-10-10
http://marc.info/?l=bugtraq&m=125787273209737&w=2 2018-10-10
http://secunia.com/advisories/36162 2018-10-10
http://secunia.com/advisories/36176 2018-10-10
http://secunia.com/advisories/36180 2018-10-10
http://secunia.com/advisories/36199 2018-10-10
http://secunia.com/advisories/36248 2018-10-10
http://secunia.com/advisories/37300 2018-10-10
http://secunia.com/advisories/37386 2018-10-10
http://secunia.com/advisories/37460 2018-10-10
http://security.gentoo.org/glsa/glsa-200911-02.xml 2018-10-10
http://www.mandriva.com/security/advisories?name=MDVSA-2009:209 2018-10-10
http://www.vupen.com/english/advisories/2009/2543 2018-10-10
http://www.vupen.com/english/advisories/2009/3316 2018-10-10
https://rhn.redhat.com/errata/RHSA-2009-1199.html 2018-10-10
https://rhn.redhat.com/errata/RHSA-2009-1200.html 2018-10-10
https://rhn.redhat.com/errata/RHSA-2009-1201.html 2018-10-10
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html 2018-10-10
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html 2018-10-10
https://access.redhat.com/security/cve/CVE-2009-2675 2010-01-14
https://bugzilla.redhat.com/show_bug.cgi?id=512920 2010-01-14
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
<= 6
Search vendor "Sun" for product "Jdk" and version " <= 6"
update_13
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_1
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_10
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_11
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_12
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_13
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_14
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_15
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_16
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_17
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_2
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_3
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_4
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_5
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_6
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_7
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_8
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_9
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_1
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_10
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_11
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_12
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_2
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_3
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_4
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_5
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_6
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_7
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_8
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_9
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
<= 6
Search vendor "Sun" for product "Jre" and version " <= 6"
update_13
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_1
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_10
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_11
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_12
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_13
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_14
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_15
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_16
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_17
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_19
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_2
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_3
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_4
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_5
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_6
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_7
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_8
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
5.0
Search vendor "Sun" for product "Jre" and version "5.0"
update_9
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_1
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_10
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_11
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_12
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_2
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_3
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_4
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_5
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_6
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_7
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_8
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
6
Search vendor "Sun" for product "Jre" and version "6"
update_9
Affected