Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.900978
Category:Denial of Service
Title:Sun Java SE Multiple Vulnerabilities (Nov 2009) - Windows
Summary:Sun Java SE is prone to multiple vulnerabilities.
Description:Summary:
Sun Java SE is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws occur due to:

- Directory traversal vulnerability in 'ICC_Profile.getInstance' method.

- Unspecified error in TrueType font parsing functionality.

- When a non-English version of Windows is used, the Java Update functionality
does not retrieve available new JRE versions.

- Failure to clone arrays that are returned by the 'getConfigurations()'
function in X11 and Win32GraphicsDevice.

- The Abstract Window Toolkit (AWT) does not properly restrict the objects
that may be sent to loggers.

- Information leak occurs as the application does not prevent the existence
of children of a resurrected ClassLoader.

- Multiple unspecified errors in the Swing implementation.

- The 'TimeZone.getTimeZone' method allows users to probe for the existence
of local files via vectors related to handling of zoneinfo.

- Error during parsing of BMP files containing UNC ICC links.

Vulnerability Impact:
Successful exploitation allows remote attacker to execute arbitrary code,
gain escalated privileges, bypass security restrictions and cause denial
of service attacks inside the context of the affected system.

Affected Software/OS:
Sun Java SE 6 prior to 6 Update 17

Sun Java SE 5 prior to 5 Update 22 on Windows.

Solution:
Upgrade to JRE version 6 Update 17 or later.

OR

Upgrade to JRE version 5 Update 22.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-3728
37386
http://secunia.com/advisories/37386
37581
http://secunia.com/advisories/37581
APPLE-SA-2009-12-03-1
http://lists.apple.com/archives/security-announce/2009/Dec/msg00000.html
APPLE-SA-2009-12-03-2
http://lists.apple.com/archives/security-announce/2009/Dec/msg00001.html
GLSA-200911-02
http://security.gentoo.org/glsa/glsa-200911-02.xml
MDVSA-2010:084
http://www.mandriva.com/security/advisories?name=MDVSA-2010:084
http://java.sun.com/j2se/1.5.0/ReleaseNotes.html
http://java.sun.com/javase/6/webnotes/6u17.html
http://support.apple.com/kb/HT3969
http://support.apple.com/kb/HT3970
https://bugzilla.redhat.com/show_bug.cgi?id=530098
oval:org.mitre.oval:def:10520
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10520
oval:org.mitre.oval:def:6657
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6657
Common Vulnerability Exposure (CVE) ID: CVE-2009-3729
https://bugzilla.redhat.com/show_bug.cgi?id=532904
oval:org.mitre.oval:def:7537
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7537
Common Vulnerability Exposure (CVE) ID: CVE-2009-3864
BugTraq ID: 36881
http://www.securityfocus.com/bid/36881
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6753
http://secunia.com/advisories/37231
http://secunia.com/advisories/37239
http://sunsolve.sun.com/search/document.do?assetkey=1-66-269868-1
SuSE Security Announcement: SUSE-SA:2009:058 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.html
http://www.vupen.com/english/advisories/2009/3131
Common Vulnerability Exposure (CVE) ID: CVE-2009-3879
https://bugzilla.redhat.com/show_bug.cgi?id=530297
oval:org.mitre.oval:def:7545
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7545
oval:org.mitre.oval:def:9568
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9568
Common Vulnerability Exposure (CVE) ID: CVE-2009-3880
https://bugzilla.redhat.com/show_bug.cgi?id=530296
oval:org.mitre.oval:def:10761
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10761
oval:org.mitre.oval:def:7316
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7316
Common Vulnerability Exposure (CVE) ID: CVE-2009-3881
https://bugzilla.redhat.com/show_bug.cgi?id=530173
oval:org.mitre.oval:def:11484
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11484
oval:org.mitre.oval:def:6906
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6906
Common Vulnerability Exposure (CVE) ID: CVE-2009-3882
https://bugzilla.redhat.com/show_bug.cgi?id=530175
oval:org.mitre.oval:def:7300
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7300
oval:org.mitre.oval:def:8841
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8841
Common Vulnerability Exposure (CVE) ID: CVE-2009-3883
oval:org.mitre.oval:def:10191
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10191
oval:org.mitre.oval:def:6968
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6968
Common Vulnerability Exposure (CVE) ID: CVE-2009-3884
https://bugzilla.redhat.com/show_bug.cgi?id=530300
oval:org.mitre.oval:def:11686
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11686
oval:org.mitre.oval:def:6960
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6960
Common Vulnerability Exposure (CVE) ID: CVE-2009-3885
https://bugzilla.redhat.com/show_bug.cgi?id=530114
oval:org.mitre.oval:def:7094
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7094
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.