CVE-2009-2475
published 2009-08-10CVE-2009-2475: Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCCINAN
EPSS
2.32%
81.5th percentile
Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables that are declared without the final keyword, related to (1) LayoutQueue, (2) Cursor.predefined, (3) AccessibleResourceBundle.getContents, (4) ImageReaderSpi.STANDARD_INPUT_TYPE, (5) ImageWriterSpi.STANDARD_OUTPUT_TYPE, (6) the imageio plugins, (7) DnsContext.debug, (8) RmfFileReader/StandardMidiFileWriter.types, (9) AbstractSaslImpl.logger, (10) Synth.Region.uiToRegionMap/lowerCaseNameMap, (11) the Introspector class and a cache of BeanInfo, and (12) JAX-WS, a different vulnerability than CVE-2009-2673.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | java_se | <= 5.0 | — |
| sun | java_se | <= 6 | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
vendor_redhat7.8HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2009-08-11·CVSS 5.0
CVE-2009-0217 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: OpenJDK vulnerabilities
It was discovered that the XML HMAC signature system did not
correctly check certain lengths. If an attacker sent a truncated
HMAC, it could bypass authentication, leading to potential privilege
escalation. (CVE-2009-0217)
It was discovered that JAR bundles would appear signed if only one element
was signed. If a user were tricked into running a malicious Java applet, a
remote attacker could exploit this to gain access to private information and
potentially run untrusted code. (CVE-2009-1896)
It was discovered that certain variables could leak information. If a
user were tricked into running a malicious Java applet, a remote attacker
could exploit this to gain access to private information and potentially
run untrusted cod
Red Hat
OpenJDK information leaks in mutable variables (6588003,6656586,6656610,6656625,6657133,6657619,6657625,6657695,6660049,6660539,6813167)
vendor_redhat·2009-08-05·CVSS 7.8
CVE-2009-2475 [HIGH] OpenJDK information leaks in mutable variables (6588003,6656586,6656610,6656625,6657133,6657619,6657625,6657695,6660049,6660539,6813167)
OpenJDK information leaks in mutable variables (6588003,6656586,6656610,6656625,6657133,6657619,6657625,6657695,6660049,6660539,6813167)
Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables that are declared without the final keyword, related to (1) LayoutQueue, (2) Cursor.predefined, (3) AccessibleResourceBundle.getContents, (4) ImageReaderSpi.STANDARD_INPUT_TYPE, (5) ImageWriterSpi.STANDARD_OUTPUT_TYPE, (6) the imageio plugins, (7) DnsContext.debug, (8) RmfFileReader/StandardMidiFileWriter.types, (9) AbstractSaslImpl.logger, (10) Synth.Region.uiToRegionMap/lowerCaseNameMap, (11) the Introspector class and a cache of BeanInfo, and (12) JAX-WS, a different vulner
GHSA
GHSA-2vx8-fp5p-f94q: Sun Java SE 5
ghsa_unreviewed·2022-05-02·CVSS 7.5
CVE-2009-2475 [HIGH] CWE-200 GHSA-2vx8-fp5p-f94q: Sun Java SE 5
Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables that are declared without the final keyword, related to (1) LayoutQueue, (2) Cursor.predefined, (3) AccessibleResourceBundle.getContents, (4) ImageReaderSpi.STANDARD_INPUT_TYPE, (5) ImageWriterSpi.STANDARD_OUTPUT_TYPE, (6) the imageio plugins, (7) DnsContext.debug, (8) RmfFileReader/StandardMidiFileWriter.types, (9) AbstractSaslImpl.logger, (10) Synth.Region.uiToRegionMap/lowerCaseNameMap, (11) the Introspector class and a cache of BeanInfo, and (12) JAX-WS, a different vulnerability than CVE-2009-2673.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-2944 ikiwiki: arbitrary file read via crafted TeX commands
bugzilla·2009-09-01·CVSS 5.0
CVE-2009-2944 [MEDIUM] CVE-2009-2944 ikiwiki: arbitrary file read via crafted TeX commands
CVE-2009-2944 ikiwiki: arbitrary file read via crafted TeX commands
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-2944 to
the following vulnerability:
Name: CVE-2009-2944
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2944
Assigned: 20090823
Reference: CONFIRM: http://ikiwiki.info/security/#index35h2
Reference: BID:36181
Reference: URL: http://www.securityfocus.com/bid/36181
Reference: SECUNIA:36516
Reference: URL: http://secunia.com/advisories/36516
Reference: VUPEN:ADV-2009-2475
Reference: URL: http://www.vupen.com/english/advisories/2009/2475
Incomplete blacklist vulnerability in the teximg plugin in ikiwiki
before 3.1415926 and 2.x before 2.53.4 allows context-dependent
attackers to read arbitrary files via crafted TeX commands.
Discussion:
This
Bugzilla
CVE-2009-2475 OpenJDK information leaks in mutable variables (6588003,6656586,6656610,6656625,6657133,6657619,6657625,6657695,6660049,6660539,6813167)
bugzilla·2009-07-22·CVSS 7.8
CVE-2009-2475 [HIGH] CVE-2009-2475 OpenJDK information leaks in mutable variables (6588003,6656586,6656610,6656625,6657133,6657619,6657625,6657695,6660049,6660539,6813167)
CVE-2009-2475 OpenJDK information leaks in mutable variables (6588003,6656586,6656610,6656625,6657133,6657619,6657625,6657695,6660049,6660539,6813167)
Several, potential information leaks were found in various mutable static
variables. These could be exploited in application scenarios that execute
untrusted scripting code.
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1
http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-22-1
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:1199 https://rhn.redhat.com/errata/RHSA-2009-1199.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:1200 https
http://java.sun.com/j2se/1.5.0/ReleaseNotes.htmlhttp://java.sun.com/javase/6/webnotes/6u15.htmlhttp://lists.apple.com/archives/security-announce/2009/Sep/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlhttp://secunia.com/advisories/36162http://secunia.com/advisories/36176http://secunia.com/advisories/36180http://secunia.com/advisories/36199http://secunia.com/advisories/37386http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-22-1http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1http://www.mandriva.com/security/advisories?name=MDVSA-2009:209http://www.vupen.com/english/advisories/2009/2543https://bugzilla.redhat.com/show_bug.cgi?id=513215https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10221https://rhn.redhat.com/errata/RHSA-2009-1199.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1200.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1201.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.htmlhttp://java.sun.com/j2se/1.5.0/ReleaseNotes.htmlhttp://java.sun.com/javase/6/webnotes/6u15.htmlhttp://lists.apple.com/archives/security-announce/2009/Sep/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlhttp://secunia.com/advisories/36162http://secunia.com/advisories/36176http://secunia.com/advisories/36180http://secunia.com/advisories/36199http://secunia.com/advisories/37386http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-22-1http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1http://www.mandriva.com/security/advisories?name=MDVSA-2009:209http://www.vupen.com/english/advisories/2009/2543https://bugzilla.redhat.com/show_bug.cgi?id=513215https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10221https://rhn.redhat.com/errata/RHSA-2009-1199.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1200.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1201.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html
2009-08-10
Published