CVE-2009-3867
published 2009-11-05CVE-2009-3867: Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and…
PriorityP279critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
73.38%
99.4th percentile
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.
Affected
136 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | bea_product_suite | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect applet requests serving a JAR file matching the CVE-2009-3867 exploit pattern — HTTP response with Content-Type application/octet-stream delivering a .jar payload from a Metasploit handler URI ↗
- →CVE-2009-3867 was bundled into exploit kits including Phoenix2, Eleonore, and Liberty — monitor for JAR file delivery from known exploit kit infrastructure ↗
- →Metasploit module targets Java 1.6.0_u11 and 1.6.0_u16 on Windows XP SP3 — flag browser requests from these JRE User-Agent strings loading remote JAR applets ↗
- →Metasploit exploit module delivers payload via HTML PARAM tags with hex-encoded shellcode — inspect applet HTML for PARAM tags containing long hex strings alongside a JAR applet load ↗
- ·The Metasploit module only confirmed exploitation on Windows x86 (XP SP3) with JRE 1.6.0_u11 and 1.6.0_u16, despite all listed versions being reportedly vulnerable; Mac OS X PPC and x86 targets exist but were not validated ↗
- ·The PoC for OSX Leopard 10.5 uses a different offset (1080 slashes) and different heap spray addresses than the Snow Leopard variant, indicating exploit parameters vary by minor OS build ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h62j-9mvm-r9mf: Stack-based buffer overflow in the HsbParser
ghsa_unreviewed·2022-05-02
CVE-2009-3867 [HIGH] CWE-119 GHSA-h62j-9mvm-r9mf: Stack-based buffer overflow in the HsbParser
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.
GHSA
GHSA-3524-9jx8-82v5: Multiple vulnerabilities in the JRockit component in BEA Product Suite R27
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2010-0079 [CRITICAL] GHSA-3524-9jx8-82v5: Multiple vulnerabilities in the JRockit component in BEA Product Suite R27
Multiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2, 5, and 6 allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this CVE identifier overlaps CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, and CVE-2009-3877.
VulnCheck
sun jdk Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2009·CVSS 9.3
CVE-2009-3867 [CRITICAL] sun jdk Improper Restriction of Operations within the Bounds of a Memory Buffer
sun jdk Improper Restriction of Operations within the Bounds of a Memory Buffer
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.
Affected: sun jdk
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.virusbulletin.com/virusbulletin/2010/05/exploit-kit-explosion-part-two-vectors-attack/; https://securelist.com/monthly-malware-statistics-may-2010/36304/; https://securelist.
Red Hat
java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303)
vendor_redhat·2009-11-03·CVSS 9.3
CVE-2009-3867 [CRITICAL] CWE-121 java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303)
java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303)
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.
No detection rules found.
Exploit-DB
Sun Java JRE - getSoundbank 'file://' URI Buffer Overflow (Metasploit)
exploitdb·2010-09-20
CVE-2009-3867 Sun Java JRE - getSoundbank 'file://' URI Buffer Overflow (Metasploit)
Sun Java JRE - getSoundbank 'file://' URI Buffer Overflow (Metasploit)
---
##
# $Id: java_getsoundbank_bof.rb 10394 2010-09-20 08:06:27Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Sun Java JRE getSoundbank file:// URI Buffer Overflow',
'Description' => %q{
This module exploits a flaw in the getSoundbank function in the Sun JVM.
The payload is serialized and passed to the applet via PARAM tags. It must be
a native payload.
The effected Java versions are JDK and JRE 6 Update 16 and earlier,
JDK and JRE 5.0 Update 21 and earli
Exploit-DB
Sun Java SE November 2009 - Multiple Vulnerabilities (1)
exploitdb·2009-10-29
CVE-2009-3867 Sun Java SE November 2009 - Multiple Vulnerabilities (1)
Sun Java SE November 2009 - Multiple Vulnerabilities (1)
---
source: https://www.securityfocus.com/bid/36881/info
Sun has released updates to address multiple security vulnerabilities in Java SE.
Successful exploits may allow attackers to bypass certain security restrictions, run untrusted applets with elevated privileges, execute arbitrary code, and cause denial-of-service conditions. Other attacks are also possible.
These issues are addressed in the following releases:
JDK and JRE 6 Update 17
JDK and JRE 5.0 Update 22
SDK and JRE 1.4.2_24
SDK and JRE 1.3.1_27
import java.awt.Graphics;
public class test extends java.applet.Applet {
public static Synthesizer synth;
Soundbank soundbank;
public void init()
{
String fName = "";
if(isWindows()){
System.out.println("This is Windows");
f
Exploit-DB
Sun Java SE November 2009 - Multiple Vulnerabilities (2)
exploitdb·2009-10-29
CVE-2009-3867 Sun Java SE November 2009 - Multiple Vulnerabilities (2)
Sun Java SE November 2009 - Multiple Vulnerabilities (2)
---
source: https://www.securityfocus.com/bid/36881/info
Sun has released updates to address multiple security vulnerabilities in Java SE.
Successful exploits may allow attackers to bypass certain security restrictions, run untrusted applets with elevated privileges, execute arbitrary code, and cause denial-of-service conditions. Other attacks are also possible.
These issues are addressed in the following releases:
JDK and JRE 6 Update 17
JDK and JRE 5.0 Update 22
SDK and JRE 1.4.2_24
SDK and JRE 1.3.1_27
*/
import javax.sound.midi.*;
import java.io.*;
import java.net.*;
import java.awt.Graphics;
public class test extends java.applet.Applet
{
public static Synthesizer synth;
Soundbank soundbank;
public void init()
{
String f
Metasploit
Sun Java JRE getSoundbank file:// URI Buffer Overflow
metasploit
Sun Java JRE getSoundbank file:// URI Buffer Overflow
Sun Java JRE getSoundbank file:// URI Buffer Overflow
This module exploits a flaw in the getSoundbank function in the Sun JVM. The payload is serialized and passed to the applet via PARAM tags. It must be a native payload. The effected Java versions are JDK and JRE 6 Update 16 and earlier, JDK and JRE 5.0 Update 21 and earlier, SDK and JRE 1.4.2_23 and earlier, and SDK and JRE 1.3.1_26 and earlier. NOTE: Although all of the above versions are reportedly vulnerable, only 1.6.0_u11 and 1.6.0_u16 on Windows XP SP3 were tested.
Zscaler
300% Increase In Malicious JARs | Zscaler
blogs_zscaler·2010-05-14·CVSS 10.0
[CRITICAL] 300% Increase In Malicious JARs | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2009-3867 java-1.5.0-sun, java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303)
bugzilla·2009-11-05·CVSS 9.3
CVE-2009-3867 [CRITICAL] CVE-2009-3867 java-1.5.0-sun, java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303)
CVE-2009-3867 java-1.5.0-sun, java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303)
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3867 to
the following vulnerability:
Stack-based buffer overflow in the HsbParser.getSoundBank function in
Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before
Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x
before 1.4.2_24 allows remote attackers to execute arbitrary code via
a long file: URL in an argument, aka Bug Id 6854303.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3867
http://zerodayinitiative.com/advisories/ZDI-09-076/
http://java.sun.com/javase/6/webnotes/6u17.html
http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1
http://w
Bugzilla
CVE-2009-3867 JRE HsbParser.getSoundBank Stack Buffer Overflow Vulnerability (6854303)
bugzilla·2009-11-04·CVSS 9.3
CVE-2009-3867 [CRITICAL] CVE-2009-3867 JRE HsbParser.getSoundBank Stack Buffer Overflow Vulnerability (6854303)
CVE-2009-3867 JRE HsbParser.getSoundBank Stack Buffer Overflow Vulnerability (6854303)
aka http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1
CR 6854303: An anonymous researcher, working with the Zero Day
Initiative (http://www.zerodayinitiative.com) and TippingPoint
(http://www.tippingpoint.com).
"Multiple buffer and integer overflow vulnerabilities in the Java
Runtime Environment with processing audio and image files may allow an
untrusted applet or Java Web Start application to escalate privileges."
Discussion:
*** This bug has been marked as a duplicate of bug 533214 ***
http://java.sun.com/javase/6/webnotes/6u17.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.htmlhttp://marc.info/?l=bugtraq&m=126566824131534&w=2http://marc.info/?l=bugtraq&m=131593453929393&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/37231http://secunia.com/advisories/37239http://secunia.com/advisories/37386http://secunia.com/advisories/37581http://secunia.com/advisories/37841http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://securitytracker.com/id?1023132http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1http://support.apple.com/kb/HT3969http://support.apple.com/kb/HT3970http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1694.htmlhttp://www.securityfocus.com/bid/36881http://www.vupen.com/english/advisories/2009/3131http://zerodayinitiative.com/advisories/ZDI-09-076/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11903https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6746https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7750http://java.sun.com/javase/6/webnotes/6u17.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.htmlhttp://marc.info/?l=bugtraq&m=126566824131534&w=2http://marc.info/?l=bugtraq&m=131593453929393&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/37231http://secunia.com/advisories/37239http://secunia.com/advisories/37386http://secunia.com/advisories/37581http://secunia.com/advisories/37841http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://securitytracker.com/id?1023132http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1http://support.apple.com/kb/HT3969http://support.apple.com/kb/HT3970http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1694.htmlhttp://www.securityfocus.com/bid/36881http://www.vupen.com/english/advisories/2009/3131http://zerodayinitiative.com/advisories/ZDI-09-076/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11903https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6746https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7750
2009-11-05
Published
Exploited in the wild