CVE-2009-1095
published 2009-03-25CVE-2009-1095: Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier…
PriorityP351critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.10%
93.5th percentile
Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.5.0 | — |
| sun | jdk | <= 1.6.0 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | <= 1.5.0 | — |
| sun | jre | <= 1.6.0 | — |
| sun | jre | — | — |
| sun | jre | — | — |
| vmware | esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
vendor_vmware·2009-11-20·CVSS 5.0
CVE-2007-2052 [MEDIUM] VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
VMSA-2009-0016: VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
a. JRE Security Update JRE update to version 1.5.0_20, which addresses multiple security issues that existed in earlier releases of JRE. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095, CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_20: CVE-2009-
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2009-03-26·CVSS 6.4
CVE-2009-1101 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: OpenJDK vulnerabilities
It was discovered that font creation could leak temporary files.
If a user were tricked into loading a malicious program or applet,
a remote attacker could consume disk space, leading to a denial of
service. (CVE-2006-2426, CVE-2009-1100)
It was discovered that the lightweight HttpServer did not correctly close
files on dataless connections. A remote attacker could send specially
crafted requests, leading to a denial of service. (CVE-2009-1101)
The Java Runtime Environment did not correctly validate certain generated
code. If a user were tricked into running a malicious applet a remote
attacker could execute arbitrary code. (CVE-2009-1102)
It was discovered that LDAP connections did not close correctly.
A remote attacker
Red Hat
OpenJDK Pack200 Buffer overflow vulnerability (6792554)
vendor_redhat·2009-03-25·CVSS 10.0
CVE-2009-1095 [CRITICAL] OpenJDK Pack200 Buffer overflow vulnerability (6792554)
OpenJDK Pack200 Buffer overflow vulnerability (6792554)
Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.
GHSA
GHSA-86hj-mfgv-6432: Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5
ghsa_unreviewed·2022-05-02
CVE-2009-1095 [HIGH] GHSA-86hj-mfgv-6432: Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5
Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-1833 Firefox JavaScript engine crashes
bugzilla·2009-06-01·CVSS 9.3
CVE-2009-1833 [CRITICAL] CVE-2009-1833 Firefox JavaScript engine crashes
CVE-2009-1833 Firefox JavaScript engine crashes
Mozilla developers and community members identified and fixed several
stability bugs in the browser engine used in Firefox and other
Mozilla-based products. Some of these crashes showed evidence of memory
corruption under certain circumstances and we presume that with enough
effort at least some of these could be exploited to run arbitrary code.
Jesse Ruderman, Adam Hauner, and Igor Bukanov reported crashes in the
Firefox 3 JavaScript engine.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 4
Via RHSA-2009:1095 https://rhn.redhat.com/errata/RHSA-2009-1095.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux
Bugzilla
CVE-2009-1832 Firefox double frame construction flaw
bugzilla·2009-06-01·CVSS 9.3
CVE-2009-1832 [CRITICAL] CVE-2009-1832 Firefox double frame construction flaw
CVE-2009-1832 Firefox double frame construction flaw
Mozilla developers and community members identified and fixed several
stability bugs in the browser engine used in Firefox and other
Mozilla-based products. Some of these crashes showed evidence of memory
corruption under certain circumstances and we presume that with enough
effort at least some of these could be exploited to run arbitrary code.
Boris Zbarsky reported a method to trigger double frame construction which
could lead to memory corruption.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 4
Via RHSA-2009:1095 https://rhn.redhat.com/errata/RHSA-2009-1095.html
---
firefox-3.0.11-1.fc10, xulrunner-1.9.0.11-1.fc10, epiphany-2.24.3-7.fc10, epiphany-extensio
Bugzilla
CVE-2009-1839 Firefox information disclosure flaw
bugzilla·2009-06-01·CVSS 5.4
CVE-2009-1839 [MEDIUM] CVE-2009-1839 Firefox information disclosure flaw
CVE-2009-1839 Firefox information disclosure flaw
Security researchers Adam Barth and Collin Jackson reported that when a
file: resource is loaded via the location bar it inherits the principal of
the previously loaded document. This vulnerability can potentially give the
newly loaded document additional privileges to access resources that it
wouldn't otherwise have, including resources in the document's parent
folder.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 4
Via RHSA-2009:1095 https://rhn.redhat.com/errata/RHSA-2009-1095.html
---
firefox-3.0.11-1.fc10, xulrunner-1.9.0.11-1.fc10, epiphany-2.24.3-7.fc10, epiphany-extensions-2.24.3-2.fc10, blam-1.8.5-11.fc10, devhelp-0.22-9.fc10, galeon-2.0.7-11.fc10, gecko-
Bugzilla
CVE-2009-1838 Firefox arbitrary code execution flaw
bugzilla·2009-06-01·CVSS 9.3
CVE-2009-1838 [CRITICAL] CVE-2009-1838 Firefox arbitrary code execution flaw
CVE-2009-1838 Firefox arbitrary code execution flaw
Mozilla security researcher moz_bug_r_a4 reported that the owner document
of an element can become null after garbage collection. In such cases,
event listeners may be executed within the wrong JavaScript context. An
attacker could potentially use this vulnerability to have a malicious event
handler execute arbitrary JavaScript with chrome privileges.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 4
Via RHSA-2009:1095 https://rhn.redhat.com/errata/RHSA-2009-1095.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Via RHSA-2009:1096 https://rhn.redhat.com/errata/RHSA-2009-1096.html
---
firefox-3.0
Bugzilla
CVE-2009-1835 Firefox Arbitrary domain cookie access by local file: resources
bugzilla·2009-06-01·CVSS 4.3
CVE-2009-1835 [MEDIUM] CVE-2009-1835 Firefox Arbitrary domain cookie access by local file: resources
CVE-2009-1835 Firefox Arbitrary domain cookie access by local file: resources
Security researcher Gregory Fleischer reported that local resources loaded
via the file: protocol can access any domain's cookies which have been
saved on a user's machine. Fleischer demonstrated that a local document's
domain was being calculated incorrectly from its URL. If a victim could be
persuaded to download a malicious file and then open that file in their
browser, the malicious file could then steal arbitrary cookies from the
victim's computer. Due to the interaction required for this attack, the
severity of the issue was determined to be moderate.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 4
Via RHSA-2009:1095 https://rhn.red
Bugzilla
CVE-2009-1837 Firefox Race condition while accessing the private data of a NPObject JS wrapper class object
bugzilla·2009-06-01·CVSS 7.5
CVE-2009-1837 [HIGH] CVE-2009-1837 Firefox Race condition while accessing the private data of a NPObject JS wrapper class object
CVE-2009-1837 Firefox Race condition while accessing the private data of a NPObject JS wrapper class object
Jakob Balle and Carsten Eiram of Secunia Research reported a race condition
in NPObjWrapper_NewResolve when accessing the properties of a NPObject, a
wrapped JSObject. Balle and Eiram demonstrated that this condition could be
reached by navigating away from a web page during the loading of a Java
applet. Under such conditions the Java object would be destroyed but later
called into resulting in a free memory read. An attacker could potentially
write to the freed memory before it is reused and run arbitrary code on the
victim's computer.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 4
Via RHSA-2009:1095 https:
Bugzilla
CVE-2009-1840 Firefox XUL scripts skip some security checks
bugzilla·2009-06-01·CVSS 9.3
CVE-2009-1840 [CRITICAL] CVE-2009-1840 Firefox XUL scripts skip some security checks
CVE-2009-1840 Firefox XUL scripts skip some security checks
Mozilla add-on developer and community member Wladimir Palant reported that
two key security checks are not being called when loading XUL scripts. The
checks which are skipped are intended to verify that content loading
policies will not be violated by loading a XUL script. Mozilla code relying
on the content policies for security, such as privileged add-ons, could
potentially be exploited to run JavaScript with elevated privileges.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 4
Via RHSA-2009:1095 https://rhn.redhat.com/errata/RHSA-2009-1095.html
---
firefox-3.0.11-1.fc10, xulrunner-1.9.0.11-1.fc10, epiphany-2.24.3-7.fc10, epiphany-extensions-2.24.3-2.f
Bugzilla
CVE-2009-1834 Firefox URL spoofing with invalid unicode characters
bugzilla·2009-06-01·CVSS 4.3
CVE-2009-1834 [MEDIUM] CVE-2009-1834 Firefox URL spoofing with invalid unicode characters
CVE-2009-1834 Firefox URL spoofing with invalid unicode characters
Mozilla add-on developer Pavel Cvrcek reported that certain invalid unicode
characters, when used as part of an IDN, are displayed as whitespace in the
location bar. This whitespace could be used to force part of the URL out of
view in the location bar. An attacker could use this vulnerability to spoof
the location bar and display a misleading URL for their malicious web page.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 4
Via RHSA-2009:1095 https://rhn.redhat.com/errata/RHSA-2009-1095.html
---
firefox-3.0.11-1.fc10, xulrunner-1.9.0.11-1.fc10, epiphany-2.24.3-7.fc10, epiphany-extensions-2.24.3-2.fc10, blam-1.8.5-11.fc10, devhelp-0.22-9.fc10, gale
Bugzilla
CVE-2009-1095 CVE-2009-1096 OpenJDK Pack200 Buffer overflow vulnerability (6792554)
bugzilla·2009-03-13·CVSS 10.0
CVE-2009-1095 [CRITICAL] CVE-2009-1095 CVE-2009-1096 OpenJDK Pack200 Buffer overflow vulnerability (6792554)
CVE-2009-1095 CVE-2009-1096 OpenJDK Pack200 Buffer overflow vulnerability (6792554)
Integer overflow in unpack200 in Java SE Development Kit (JDK) and
Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update
12 and earlier, allows remote attackers to access files or execute
arbitrary code via a JAR file with crafted Pack200 headers.
Discussion:
Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java
Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12
and earlier, allows remote attackers to access files or execute
arbitrary code via a JAR file with crafted Pack200 headers. (CVE-2009-1096)
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:0392 https://rhn.redhat.c
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=781http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.htmlhttp://marc.info/?l=bugtraq&m=124344236532162&w=2http://secunia.com/advisories/34489http://secunia.com/advisories/34495http://secunia.com/advisories/34496http://secunia.com/advisories/34632http://secunia.com/advisories/34675http://secunia.com/advisories/35156http://secunia.com/advisories/35223http://secunia.com/advisories/35255http://secunia.com/advisories/35416http://secunia.com/advisories/35776http://secunia.com/advisories/36185http://secunia.com/advisories/37386http://secunia.com/advisories/37460http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-254570-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020225.1-1http://support.avaya.com/elmodocs2/security/ASA-2009-108.htmhttp://support.avaya.com/elmodocs2/security/ASA-2009-109.htmhttp://www.debian.org/security/2009/dsa-1769http://www.mandriva.com/security/advisories?name=MDVSA-2009:137http://www.mandriva.com/security/advisories?name=MDVSA-2009:162http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0392.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0394.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1038.htmlhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/34240http://www.securitytracker.com/id?1021894http://www.ubuntu.com/usn/usn-748-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/1426http://www.vupen.com/english/advisories/2009/3316https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10124https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6643https://rhn.redhat.com/errata/RHSA-2009-0377.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1198.htmlhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=781http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.htmlhttp://marc.info/?l=bugtraq&m=124344236532162&w=2http://secunia.com/advisories/34489http://secunia.com/advisories/34495http://secunia.com/advisories/34496http://secunia.com/advisories/34632http://secunia.com/advisories/34675http://secunia.com/advisories/35156http://secunia.com/advisories/35223http://secunia.com/advisories/35255http://secunia.com/advisories/35416http://secunia.com/advisories/35776http://secunia.com/advisories/36185http://secunia.com/advisories/37386http://secunia.com/advisories/37460http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-254570-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020225.1-1http://support.avaya.com/elmodocs2/security/ASA-2009-108.htmhttp://support.avaya.com/elmodocs2/security/ASA-2009-109.htmhttp://www.debian.org/security/2009/dsa-1769http://www.mandriva.com/security/advisories?name=MDVSA-2009:137http://www.mandriva.com/security/advisories?name=MDVSA-2009:162http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0392.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0394.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1038.htmlhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/34240http://www.securitytracker.com/id?1021894http://www.ubuntu.com/usn/usn-748-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/1426http://www.vupen.com/english/advisories/2009/3316https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10124https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6643https://rhn.redhat.com/errata/RHSA-2009-0377.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1198.html
2009-03-25
Published