CVE-2009-1094
published 2009-03-25CVE-2009-1094: Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12…
PriorityP349critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.39%
90.2th percentile
Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.
Affected
107 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.5.0 | — |
| sun | jdk | <= 1.6.0 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | <= 1.5.0 | — |
| sun | jre | <= 1.6.0 | — |
| sun | jre | <= 1.3.1_24 | — |
| sun | jre | <= 1.4.2_19 | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv7.5HIGH
vendor_redhat10.0CRITICAL
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kdelibs: SSL certificate for IP address accepted as valid for hosts that resolve to the IP
vendor_redhat·2011-01-31·CVSS 7.5
CVE-2011-1094 [HIGH] kdelibs: SSL certificate for IP address accepted as valid for hosts that resolve to the IP
kdelibs: SSL certificate for IP address accepted as valid for hosts that resolve to the IP
kio/kio/tcpslavebase.cpp in KDE KSSL in kdelibs before 4.6.1 does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a certificate issued by a legitimate Certification Authority for an IP address, a different vulnerability than CVE-2009-2702.
VMware
VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
vendor_vmware·2009-11-20·CVSS 5.0
CVE-2007-2052 [MEDIUM] VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
VMSA-2009-0016: VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
a. JRE Security Update JRE update to version 1.5.0_20, which addresses multiple security issues that existed in earlier releases of JRE. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095, CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_20: CVE-2009-
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2009-03-26·CVSS 6.4
CVE-2009-1101 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: OpenJDK vulnerabilities
It was discovered that font creation could leak temporary files.
If a user were tricked into loading a malicious program or applet,
a remote attacker could consume disk space, leading to a denial of
service. (CVE-2006-2426, CVE-2009-1100)
It was discovered that the lightweight HttpServer did not correctly close
files on dataless connections. A remote attacker could send specially
crafted requests, leading to a denial of service. (CVE-2009-1101)
The Java Runtime Environment did not correctly validate certain generated
code. If a user were tricked into running a malicious applet a remote
attacker could execute arbitrary code. (CVE-2009-1102)
It was discovered that LDAP connections did not close correctly.
A remote attacker
Red Hat
OpenJDK LDAP client remote code execution (6737315)
vendor_redhat·2009-03-25·CVSS 10.0
CVE-2009-1094 [CRITICAL] OpenJDK LDAP client remote code execution (6737315)
OpenJDK LDAP client remote code execution (6737315)
Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.
GHSA
GHSA-5w5h-m7x5-fq48: Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5
ghsa_unreviewed·2022-05-02
CVE-2009-1094 [HIGH] GHSA-5w5h-m7x5-fq48: Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5
Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.
OSV
CVE-2011-1094: kio/kio/tcpslavebase
osv·2011-03-16·CVSS 7.5
CVE-2011-1094 CVE-2011-1094: kio/kio/tcpslavebase
kio/kio/tcpslavebase.cpp in KDE KSSL in kdelibs before 4.6.1 does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a certificate issued by a legitimate Certification Authority for an IP address, a different vulnerability than CVE-2009-2702.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-3149 OpenJDK: Incomplete enforcement of the trustURLCodebase restriction (JNDI, 8199177)
bugzilla·2018-10-16·CVSS 10.0
CVE-2018-3149 [CRITICAL] CVE-2018-3149 OpenJDK: Incomplete enforcement of the trustURLCodebase restriction (JNDI, 8199177)
CVE-2018-3149 OpenJDK: Incomplete enforcement of the trustURLCodebase restriction (JNDI, 8199177)
It was discovered that the JNDI comment of OpenJDK did not properly enforce the restriction controlled by the com.sun.jndi.ldap.object.trustURLCodebase system property. In certain cases, a Java LDAP client could unexpectedly load and execute code form an LDAP server.
Discussion:
The restriction on loading classes from remote URL and the com.sun.jndi.ldap.object.trustURLCodebase system property was introduced via this commit:
http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/255dcd4f19b6
as the fix for CVE-2009-1094.
---
Public now via Oracle CPU October 2018:
https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html#AppendixJAVA
The issue was fixed in Oracle JDK 11.0.1
Bugzilla
CVE-2009-1094 OpenJDK LDAP client remote code execution (6737315)
bugzilla·2009-03-13·CVSS 10.0
CVE-2009-1094 [CRITICAL] CVE-2009-1094 OpenJDK LDAP client remote code execution (6737315)
CVE-2009-1094 OpenJDK LDAP client remote code execution (6737315)
An unspecified vulnerability in the LDAP implementation in Java SE
Development Kit (JDK) and Java Runtime Environment (JRE) allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.
5.0 Update 17 and earlier;
6 Update 12 and earlier;
SDK and JRE 1.3.1_24 and earlier;
and 1.4.2_19 and earlier
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:0392 https://rhn.redhat.com/errata/RHSA-2009-0392.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:0394 https://rhn.redhat.com/errata/RHSA-2009-0394.html
---
This issue
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.htmlhttp://marc.info/?l=bugtraq&m=124344236532162&w=2http://secunia.com/advisories/34489http://secunia.com/advisories/34495http://secunia.com/advisories/34496http://secunia.com/advisories/34632http://secunia.com/advisories/34675http://secunia.com/advisories/35156http://secunia.com/advisories/35223http://secunia.com/advisories/35255http://secunia.com/advisories/35416http://secunia.com/advisories/35776http://secunia.com/advisories/36185http://secunia.com/advisories/37386http://secunia.com/advisories/37460http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-19-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-254569-1http://support.avaya.com/elmodocs2/security/ASA-2009-108.htmhttp://support.avaya.com/elmodocs2/security/ASA-2009-109.htmhttp://www.debian.org/security/2009/dsa-1769http://www.mandriva.com/security/advisories?name=MDVSA-2009:137http://www.mandriva.com/security/advisories?name=MDVSA-2009:162http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0392.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0394.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1038.htmlhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/34240http://www.securitytracker.com/id?1021893http://www.ubuntu.com/usn/usn-748-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/1426http://www.vupen.com/english/advisories/2009/1900http://www.vupen.com/english/advisories/2009/3316https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11064https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6598https://rhn.redhat.com/errata/RHSA-2009-0377.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1198.htmlhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.htmlhttp://marc.info/?l=bugtraq&m=124344236532162&w=2http://secunia.com/advisories/34489http://secunia.com/advisories/34495http://secunia.com/advisories/34496http://secunia.com/advisories/34632http://secunia.com/advisories/34675http://secunia.com/advisories/35156http://secunia.com/advisories/35223http://secunia.com/advisories/35255http://secunia.com/advisories/35416http://secunia.com/advisories/35776http://secunia.com/advisories/36185http://secunia.com/advisories/37386http://secunia.com/advisories/37460http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-19-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-254569-1http://support.avaya.com/elmodocs2/security/ASA-2009-108.htmhttp://support.avaya.com/elmodocs2/security/ASA-2009-109.htmhttp://www.debian.org/security/2009/dsa-1769http://www.mandriva.com/security/advisories?name=MDVSA-2009:137http://www.mandriva.com/security/advisories?name=MDVSA-2009:162http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0392.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0394.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1038.htmlhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/34240http://www.securitytracker.com/id?1021893http://www.ubuntu.com/usn/usn-748-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/1426http://www.vupen.com/english/advisories/2009/1900http://www.vupen.com/english/advisories/2009/3316https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11064https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6598https://rhn.redhat.com/errata/RHSA-2009-0377.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1198.html
2009-03-25
Published