9.3

CVE-2009-1098

Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files or execute arbitrary code via a crafted GIF image, aka CR 6804998.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sun ≫ Jdk Update update17 Version <= 1.5.0
Sun ≫ Jdk Update update_12 Version <= 1.6.0
Sun ≫ Jdk Version 1.5.0
Sun ≫ Jdk Version 1.5.0 Update update1
Sun ≫ Jdk Version 1.5.0 Update update10
Sun ≫ Jdk Version 1.5.0 Update update11
Sun ≫ Jdk Version 1.5.0 Update update11_b03
Sun ≫ Jdk Version 1.5.0 Update update12
Sun ≫ Jdk Version 1.5.0 Update update13
Sun ≫ Jdk Version 1.5.0 Update update14
Sun ≫ Jdk Version 1.5.0 Update update15
Sun ≫ Jdk Version 1.5.0 Update update16
Sun ≫ Jdk Version 1.5.0 Update update2
Sun ≫ Jdk Version 1.5.0 Update update3
Sun ≫ Jdk Version 1.5.0 Update update4
Sun ≫ Jdk Version 1.5.0 Update update5
Sun ≫ Jdk Version 1.5.0 Update update6
Sun ≫ Jdk Version 1.5.0 Update update7
Sun ≫ Jdk Version 1.5.0 Update update7_b03
Sun ≫ Jdk Version 1.5.0 Update update8
Sun ≫ Jdk Version 1.5.0 Update update9
Sun ≫ Jdk Version 1.6.0 Update update_10
Sun ≫ Jdk Version 1.6.0 Update update_11
Sun ≫ Jdk Version 1.6.0 Update update_3
Sun ≫ Jdk Version 1.6.0 Update update_4
Sun ≫ Jdk Version 1.6.0 Update update_5
Sun ≫ Jdk Version 1.6.0 Update update_6
Sun ≫ Jdk Version 1.6.0 Update update_7
Sun ≫ Jdk Version 1.6.0 Update update1
Sun ≫ Jdk Version 1.6.0 Update update2
Sun ≫ Jre Update update17 Version <= 1.5.0
Sun ≫ Jre Update update_12 Version <= 1.6.0
Sun ≫ Jre Version 1.5.0
Sun ≫ Jre Version 1.5.0 Update update1
Sun ≫ Jre Version 1.5.0 Update update10
Sun ≫ Jre Version 1.5.0 Update update11
Sun ≫ Jre Version 1.5.0 Update update12
Sun ≫ Jre Version 1.5.0 Update update13
Sun ≫ Jre Version 1.5.0 Update update14
Sun ≫ Jre Version 1.5.0 Update update15
Sun ≫ Jre Version 1.5.0 Update update16
Sun ≫ Jre Version 1.5.0 Update update2
Sun ≫ Jre Version 1.5.0 Update update3
Sun ≫ Jre Version 1.5.0 Update update4
Sun ≫ Jre Version 1.5.0 Update update5
Sun ≫ Jre Version 1.5.0 Update update6
Sun ≫ Jre Version 1.5.0 Update update7
Sun ≫ Jre Version 1.5.0 Update update8
Sun ≫ Jre Version 1.5.0 Update update9
Sun ≫ Jre Version 1.6.0
Sun ≫ Jre Version 1.6.0 Update update_1
Sun ≫ Jre Version 1.6.0 Update update_10
Sun ≫ Jre Version 1.6.0 Update update_11
Sun ≫ Jre Version 1.6.0 Update update_2
Sun ≫ Jre Version 1.6.0 Update update_3
Sun ≫ Jre Version 1.6.0 Update update_4
Sun ≫ Jre Version 1.6.0 Update update_5
Sun ≫ Jre Version 1.6.0 Update update_6
Sun ≫ Jre Version 1.6.0 Update update_7
Sun ≫ Jre Version <= 1.3.1_24
Sun ≫ Jre Version 1.3.1
Sun ≫ Jre Version 1.3.1_01
Sun ≫ Jre Version 1.3.1_2
Sun ≫ Jre Version 1.3.1_03
Sun ≫ Jre Version 1.3.1_04
Sun ≫ Jre Version 1.3.1_05
Sun ≫ Jre Version 1.3.1_06
Sun ≫ Jre Version 1.3.1_07
Sun ≫ Jre Version 1.3.1_08
Sun ≫ Jre Version 1.3.1_09
Sun ≫ Jre Version 1.3.1_10
Sun ≫ Jre Version 1.3.1_11
Sun ≫ Jre Version 1.3.1_12
Sun ≫ Jre Version 1.3.1_13
Sun ≫ Jre Version 1.3.1_14
Sun ≫ Jre Version 1.3.1_15
Sun ≫ Jre Version 1.3.1_16
Sun ≫ Jre Version 1.3.1_17
Sun ≫ Jre Version 1.3.1_18
Sun ≫ Jre Version 1.3.1_19
Sun ≫ Jre Version 1.3.1_20
Sun ≫ Jre Version 1.3.1_21
Sun ≫ Jre Version 1.3.1_22
Sun ≫ Jre Version 1.3.1_23
Sun ≫ Sdk Version <= 1.3.1_24
Sun ≫ Sdk Version 1.3.1
Sun ≫ Sdk Version 1.3.1_01
Sun ≫ Sdk Version 1.3.1_01a
Sun ≫ Sdk Version 1.3.1_02
Sun ≫ Sdk Version 1.3.1_03
Sun ≫ Sdk Version 1.3.1_04
Sun ≫ Sdk Version 1.3.1_05
Sun ≫ Sdk Version 1.3.1_06
Sun ≫ Sdk Version 1.3.1_07
Sun ≫ Sdk Version 1.3.1_08
Sun ≫ Sdk Version 1.3.1_09
Sun ≫ Sdk Version 1.3.1_10
Sun ≫ Sdk Version 1.3.1_11
Sun ≫ Sdk Version 1.3.1_12
Sun ≫ Sdk Version 1.3.1_13
Sun ≫ Sdk Version 1.3.1_14
Sun ≫ Sdk Version 1.3.1_15
Sun ≫ Sdk Version 1.3.1_16
Sun ≫ Sdk Version 1.3.1_17
Sun ≫ Sdk Version 1.3.1_18
Sun ≫ Sdk Version 1.3.1_19
Sun ≫ Sdk Version 1.3.1_20
Sun ≫ Sdk Version 1.3.1_21
Sun ≫ Sdk Version 1.3.1_22
Sun ≫ Sdk Version 1.3.1_23
Sun ≫ Jre Version <= 1.4.2_19
Sun ≫ Jre Version 1.4.2
Sun ≫ Jre Version 1.4.2_1
Sun ≫ Jre Version 1.4.2_2
Sun ≫ Jre Version 1.4.2_3
Sun ≫ Jre Version 1.4.2_4
Sun ≫ Jre Version 1.4.2_5
Sun ≫ Jre Version 1.4.2_6
Sun ≫ Jre Version 1.4.2_7
Sun ≫ Jre Version 1.4.2_8
Sun ≫ Jre Version 1.4.2_9
Sun ≫ Jre Version 1.4.2_10
Sun ≫ Jre Version 1.4.2_11
Sun ≫ Jre Version 1.4.2_12
Sun ≫ Jre Version 1.4.2_13
Sun ≫ Jre Version 1.4.2_14
Sun ≫ Jre Version 1.4.2_15
Sun ≫ Jre Version 1.4.2_16
Sun ≫ Jre Version 1.4.2_17
Sun ≫ Jre Version 1.4.2_18
Sun ≫ Sdk Version <= 1.4.2_19
Sun ≫ Sdk Version 1.4.2
Sun ≫ Sdk Version 1.4.2_1
Sun ≫ Sdk Version 1.4.2_2
Sun ≫ Sdk Version 1.4.2_02
Sun ≫ Sdk Version 1.4.2_03
Sun ≫ Sdk Version 1.4.2_3
Sun ≫ Sdk Version 1.4.2_04
Sun ≫ Sdk Version 1.4.2_4
Sun ≫ Sdk Version 1.4.2_5
Sun ≫ Sdk Version 1.4.2_6
Sun ≫ Sdk Version 1.4.2_7
Sun ≫ Sdk Version 1.4.2_08
Sun ≫ Sdk Version 1.4.2_09
Sun ≫ Sdk Version 1.4.2_10
Sun ≫ Sdk Version 1.4.2_11
Sun ≫ Sdk Version 1.4.2_12
Sun ≫ Sdk Version 1.4.2_13
Sun ≫ Sdk Version 1.4.2_14
Sun ≫ Sdk Version 1.4.2_15
Sun ≫ Sdk Version 1.4.2_16
Sun ≫ Sdk Version 1.4.2_17
Sun ≫ Sdk Version 1.4.2_18
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.79% 0.932
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://secunia.com/advisories/34489
http://secunia.com/advisories/34495
http://secunia.com/advisories/34496
http://secunia.com/advisories/34632
http://secunia.com/advisories/34675
http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm
http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm
http://www.debian.org/security/2009/dsa-1769
http://www.mandriva.com/security/advisories?name=MDVSA-2009:137
http://www.mandriva.com/security/advisories?name=MDVSA-2009:162
http://www.redhat.com/support/errata/RHSA-2009-0392.html
http://www.redhat.com/support/errata/RHSA-2009-0394.html
http://www.ubuntu.com/usn/usn-748-1
https://rhn.redhat.com/errata/RHSA-2009-0377.html
http://www.securityfocus.com/archive/1/507985/100/0/threaded
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
http://www.vupen.com/english/advisories/2009/3316
http://secunia.com/advisories/37460
http://secunia.com/advisories/37386
http://security.gentoo.org/glsa/glsa-200911-02.xml
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html
http://secunia.com/advisories/35416
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133
http://secunia.com/advisories/35255
http://www.vupen.com/english/advisories/2009/1426
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html
http://marc.info/?l=bugtraq&m=124344236532162&w=2
http://secunia.com/advisories/35156
http://secunia.com/advisories/35223
http://secunia.com/advisories/35776
http://secunia.com/advisories/36185
http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html
http://www.redhat.com/support/errata/RHSA-2009-1038.html
http://www.securityfocus.com/bid/34240
https://rhn.redhat.com/errata/RHSA-2009-1198.html
http://sunsolve.sun.com/search/document.do?assetkey=1-26-254571-1
Patch
Vendor Advisory
http://www.securitytracker.com/id?1021913
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6008
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9956