cbcvebase.
CVE-2009-3867
published 2009-11-05

CVE-2009-3867: Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and…

PriorityP279critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
73.38%
99.4th percentile
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.

Affected

136 ranges· showing 25
VendorProductVersion rangeFixed in
oraclebea_product_suite
sunjdk
sunjdk
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre
sunjre

Detection & IOCsextracted from sources · hover to see the quote

pathdata/exploits/CVE-2009-3867.jar
commandMidiSystem.getSoundbank(new URL(fName))
  • Detect applet requests serving a JAR file matching the CVE-2009-3867 exploit pattern — HTTP response with Content-Type application/octet-stream delivering a .jar payload from a Metasploit handler URI
  • CVE-2009-3867 was bundled into exploit kits including Phoenix2, Eleonore, and Liberty — monitor for JAR file delivery from known exploit kit infrastructure
  • Metasploit module targets Java 1.6.0_u11 and 1.6.0_u16 on Windows XP SP3 — flag browser requests from these JRE User-Agent strings loading remote JAR applets
  • Metasploit exploit module delivers payload via HTML PARAM tags with hex-encoded shellcode — inspect applet HTML for PARAM tags containing long hex strings alongside a JAR applet load
  • ·The Metasploit module only confirmed exploitation on Windows x86 (XP SP3) with JRE 1.6.0_u11 and 1.6.0_u16, despite all listed versions being reportedly vulnerable; Mac OS X PPC and x86 targets exist but were not validated
  • ·The PoC for OSX Leopard 10.5 uses a different offset (1080 slashes) and different heap spray addresses than the Snow Leopard variant, indicating exploit parameters vary by minor OS build

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.