CVE-2009-1100
published 2009-03-25CVE-2009-1100: Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.58%
88.1th percentile
Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attackers to cause a denial of service (disk consumption) via vectors related to temporary font files and (1) "limits on Font creation," aka CR 6522586, and (2) another unspecified vector, aka CR 6632886.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.5.0 | — |
| sun | jdk | <= 1.6.0 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | <= 1.5.0 | — |
| sun | jre | <= 1.6.0 | — |
| sun | jre | — | — |
| sun | jre | — | — |
| vmware | esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_ubuntu6.4MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mh7w-frv3-83jh: Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5
ghsa_unreviewed·2022-05-02
CVE-2009-1100 [MEDIUM] GHSA-mh7w-frv3-83jh: Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5
Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attackers to cause a denial of service (disk consumption) via vectors related to temporary font files and (1) "limits on Font creation," aka CR 6522586, and (2) another unspecified vector, aka CR 6632886.
VMware
VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
vendor_vmware·2009-11-20·CVSS 5.0
CVE-2007-2052 [MEDIUM] VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
VMSA-2009-0016: VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
a. JRE Security Update JRE update to version 1.5.0_20, which addresses multiple security issues that existed in earlier releases of JRE. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095, CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_20: CVE-2009-
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2009-03-26·CVSS 6.4
CVE-2009-1101 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: OpenJDK vulnerabilities
It was discovered that font creation could leak temporary files.
If a user were tricked into loading a malicious program or applet,
a remote attacker could consume disk space, leading to a denial of
service. (CVE-2006-2426, CVE-2009-1100)
It was discovered that the lightweight HttpServer did not correctly close
files on dataless connections. A remote attacker could send specially
crafted requests, leading to a denial of service. (CVE-2009-1101)
The Java Runtime Environment did not correctly validate certain generated
code. If a user were tricked into running a malicious applet a remote
attacker could execute arbitrary code. (CVE-2009-1102)
It was discovered that LDAP connections did not close correctly.
A remote attacker
Red Hat
OpenJDK: DoS (disk consumption) via handling of temporary font files
vendor_redhat·2009-03-23·CVSS 5.0
CVE-2009-1100 [MEDIUM] OpenJDK: DoS (disk consumption) via handling of temporary font files
OpenJDK: DoS (disk consumption) via handling of temporary font files
Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attackers to cause a denial of service (disk consumption) via vectors related to temporary font files and (1) "limits on Font creation," aka CR 6522586, and (2) another unspecified vector, aka CR 6632886.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-1268 Wireshark CHAP dissector crash
bugzilla·2009-04-09·CVSS 4.3
CVE-2009-1268 [MEDIUM] CVE-2009-1268 Wireshark CHAP dissector crash
CVE-2009-1268 Wireshark CHAP dissector crash
The Wireshark Check Point High-Availability Protocol (CPHAP) dissector
could crash. (Upstream Bug 3269) Versions affected: 0.9.6 to 1.0.6
http://www.wireshark.org/security/wnpa-sec-2009-02.html
Discussion:
wireshark-1.0.7-1.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
---
wireshark-1.0.8-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 4
Via RHSA-2009:1100 https://rhn.redhat.com/errata/RHSA-2009-1100.html
Bugzilla
CVE-2009-1269 Wireshark Tektronix .rf5 file crash
bugzilla·2009-04-09·CVSS 5.0
CVE-2009-1269 [MEDIUM] CVE-2009-1269 Wireshark Tektronix .rf5 file crash
CVE-2009-1269 Wireshark Tektronix .rf5 file crash
Wireshark could crash while loading a Tektronix .rf5 file.
(Upstream Bug 3366)
Versions affected: 0.99.6 to 1.0.6
http://www.wireshark.org/security/wnpa-sec-2009-02.html
Discussion:
wireshark-1.0.7-1.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
---
wireshark-1.0.8-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 4
Via RHSA-2009:1100 https://rhn.redhat.com/errata/RHSA-2009-1100.html
Bugzilla
CVE-2009-1100 OpenJDK: DoS (disk consumption) via handling of temporary font files
bugzilla·2009-03-26·CVSS 5.0
CVE-2009-1100 [MEDIUM] CVE-2009-1100 OpenJDK: DoS (disk consumption) via handling of temporary font files
CVE-2009-1100 OpenJDK: DoS (disk consumption) via handling of temporary font files
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-1100 to
the following vulnerability:
Multiple unspecified vulnerabilities in Java SE Development Kit (JDK)
and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6
Update 12 and earlier, allow remote attackers to cause a denial of
service (disk consumption) via vectors related to temporary font files
and (1) "limits on Font creation," aka CR 6522586, and (2) another
unspecified vector, aka CR 6632886.
References:
http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-19-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-254608-1
Discussion:
This issue has been addressed in following products:
Extras for RHE
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.htmlhttp://marc.info/?l=bugtraq&m=124344236532162&w=2http://secunia.com/advisories/34489http://secunia.com/advisories/34495http://secunia.com/advisories/34496http://secunia.com/advisories/35156http://secunia.com/advisories/35223http://secunia.com/advisories/35255http://secunia.com/advisories/35416http://secunia.com/advisories/35776http://secunia.com/advisories/36185http://secunia.com/advisories/37386http://secunia.com/advisories/37460http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-19-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-254608-1http://support.avaya.com/elmodocs2/security/ASA-2009-108.htmhttp://support.avaya.com/elmodocs2/security/ASA-2009-109.htmhttp://www.oracle.com/technetwork/topics/security/cpujul2009-091332.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0392.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0394.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1038.htmlhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/34240http://www.securitytracker.com/id?1021917http://www.ubuntu.com/usn/usn-748-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/1426http://www.vupen.com/english/advisories/2009/3316https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6224https://rhn.redhat.com/errata/RHSA-2009-1198.htmlhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.htmlhttp://marc.info/?l=bugtraq&m=124344236532162&w=2http://secunia.com/advisories/34489http://secunia.com/advisories/34495http://secunia.com/advisories/34496http://secunia.com/advisories/35156http://secunia.com/advisories/35223http://secunia.com/advisories/35255http://secunia.com/advisories/35416http://secunia.com/advisories/35776http://secunia.com/advisories/36185http://secunia.com/advisories/37386http://secunia.com/advisories/37460http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-19-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-254608-1http://support.avaya.com/elmodocs2/security/ASA-2009-108.htmhttp://support.avaya.com/elmodocs2/security/ASA-2009-109.htmhttp://www.oracle.com/technetwork/topics/security/cpujul2009-091332.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0392.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0394.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1038.htmlhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/34240http://www.securitytracker.com/id?1021917http://www.ubuntu.com/usn/usn-748-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/1426http://www.vupen.com/english/advisories/2009/3316https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6224https://rhn.redhat.com/errata/RHSA-2009-1198.html
2009-03-25
Published