cbcvebase.
CVE-2009-2675
published 2009-08-05

CVE-2009-2675: Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows…

critical10CVSS 3.1
AVNACLAuNCCICAC
Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.

Affected

12 ranges
VendorProductVersion rangeFixed in
oraclebea_product_suite
sunjdk<= 6
sunjdk
sunjdk
sunjre<= 6
sunjre
sunjre
vmwareesxi
vmwarevmware_tools
vmwarevmware_vcenter_server
vmwarevmware_vsphere
vmwarevmware_workstation