CVE-2009-3869
published 2009-11-05CVE-2009-3869: Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0…
PriorityP273critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
65.46%
99.2th percentile
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.
Affected
136 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | bea_product_suite | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit delivers a malicious JAR file via HTTP; detect HTTP responses serving a .jar file with Content-Type 'application/octet-stream' and 'Pragma: no-cache' headers from a browser-facing server, especially when preceded by an HTML page containing serialized payload data in PARAM tags. ↗
- →The exploit HTML page passes a serialized native payload to the applet via PARAM tags; inspect applet HTML for PARAM tags containing hex-encoded shellcode blobs. ↗
- →The Metasploit module uses a randomly named JAR (32 random alphanumeric chars + '.jar') served from the exploit URI; detect requests for randomly named .jar files from Java user-agents in browser traffic. ↗
- →The exploit targets Sun JRE versions 1.6.0_u11 and 1.6.0_u16 on Windows XP SP3; alert on Java plugin User-Agent strings indicating these specific versions in combination with JAR download activity. ↗
- →The exploit module is located at multi/browser/java_setdifficm_bof; Metasploit handler traffic can be identified by the module's URI pattern and the redirect behavior (server redirects to base path ending with '/'). ↗
- ·The Metasploit module payload space is limited to 1024 bytes and BadChars is empty; native payloads only — Java/interpreted payloads will not work with this exploit. ↗
- ·Automatic target detection is disabled in the module; the operator must manually select the target platform (Windows x86, Mac OS X PPC, or Mac OS X x86). ↗
- ·Vulnerable versions span multiple JRE/JDK branches: JDK and JRE 6 Update 16 and earlier, JDK and JRE 5.0 Update 21 and earlier, SDK and JRE 1.4.2_23 and earlier, and SDK and JRE 1.3.1_26 and earlier. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu5.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2009-11-12·CVSS 5.1
CVE-2009-3728 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: OpenJDK vulnerabilities
Dan Kaminsky discovered that SSL certificates signed with MD2 could be
spoofed given enough time. As a result, an attacker could potentially
create a malicious trusted certificate to impersonate another site. This
update handles this issue by completely disabling MD2 for certificate
validation in OpenJDK. (CVE-2009-2409)
It was discovered that ICC profiles could be identified with
".." pathnames. If a user were tricked into running a specially
crafted applet, a remote attacker could gain information about a local
system. (CVE-2009-3728)
Peter Vreugdenhil discovered multiple flaws in the processing of graphics
in the AWT library. If a user were tricked into running a specially
crafted applet, a remote attacker could crash t
Red Hat
OpenJDK JRE AWT setDifflCM stack overflow (6872357)
vendor_redhat·2009-11-03·CVSS 9.3
CVE-2009-3869 [CRITICAL] OpenJDK JRE AWT setDifflCM stack overflow (6872357)
OpenJDK JRE AWT setDifflCM stack overflow (6872357)
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.
GHSA
GHSA-xf34-q2g4-cjm6: Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK an
ghsa_unreviewed·2022-05-02
CVE-2009-3869 [HIGH] CWE-119 GHSA-xf34-q2g4-cjm6: Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK an
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.
GHSA
GHSA-3524-9jx8-82v5: Multiple vulnerabilities in the JRockit component in BEA Product Suite R27
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2010-0079 [CRITICAL] GHSA-3524-9jx8-82v5: Multiple vulnerabilities in the JRockit component in BEA Product Suite R27
Multiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2, 5, and 6 allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this CVE identifier overlaps CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, and CVE-2009-3877.
No detection rules found.
Exploit-DB
Sun Java - JRE AWT setDiffICM Buffer Overflow (Metasploit)
exploitdb·2010-09-20
CVE-2009-3869 Sun Java - JRE AWT setDiffICM Buffer Overflow (Metasploit)
Sun Java - JRE AWT setDiffICM Buffer Overflow (Metasploit)
---
##
# $Id: java_setdifficm_bof.rb 10394 2010-09-20 08:06:27Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Sun Java JRE AWT setDiffICM Buffer Overflow',
'Description' => %q{
This module exploits a flaw in the setDiffICM function in the Sun JVM.
The payload is serialized and passed to the applet via PARAM tags. It must be
a native payload.
The effected Java versions are JDK and JRE 6 Update 16 and earlier,
JDK and JRE 5.0 Update 21 and earlier, SDK and JRE 1.4.2_23 a
Metasploit
Sun Java JRE AWT setDiffICM Buffer Overflow
metasploit
Sun Java JRE AWT setDiffICM Buffer Overflow
Sun Java JRE AWT setDiffICM Buffer Overflow
This module exploits a flaw in the setDiffICM function in the Sun JVM. The payload is serialized and passed to the applet via PARAM tags. It must be a native payload. The effected Java versions are JDK and JRE 6 Update 16 and earlier, JDK and JRE 5.0 Update 21 and earlier, SDK and JRE 1.4.2_23 and earlier, and SDK and JRE 1.3.1_26 and earlier. NOTE: Although all of the above versions are reportedly vulnerable, only 1.6.0_u11 and 1.6.0_u16 on Windows XP SP3 were tested.
Bugzilla
CVE-2009-3869 OpenJDK JRE AWT setDifflCM stack overflow (6872357)
bugzilla·2009-10-21·CVSS 9.3
CVE-2009-3869 [CRITICAL] CVE-2009-3869 OpenJDK JRE AWT setDifflCM stack overflow (6872357)
CVE-2009-3869 OpenJDK JRE AWT setDifflCM stack overflow (6872357)
A buffer overflow vulnerability in the Java Runtime Environment
with processing image files may allow an untrusted applet or
Java Web Start application to escalate privileges. For example,
an untrusted applet may grant itself permissions to read and write
local files or execute local applications that are accessible to
the user running the untrusted applet.
Discussion:
*** Bug 533219 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:1560 https://rhn.redhat.com/errata/RHSA-2009-1560.html
---
java-1.6.0-openjdk-1.6.0.0-33.b16.fc12 has been submitted as an update for Fedora 12.
http://admin.fedor
Securelist
Investigation Report for the September 2014 Equation malware detection incident in the US
blogs_securelist·2017-11-16
Investigation Report for the September 2014 Equation malware detection incident in the US
Authors
- Kaspersky
## Background
In early October, a story was published by the Wall Street Journal alleging Kaspersky Lab software was used to siphon classified data from an NSA employee’s home computer system. Given that Kaspersky Lab has been at the forefront of fighting cyberespionage and cybercriminal activities on the Internet for over 20 years now, these allegations were treated very seriously. To assist any independent investigators and all the people who have been asking us questions whether those allegations were true, we decided to conduct an internal investigation to attempt to answer a few questions we had related to the article and some others that followed it:
1. Was our software used outside of its intended functionality to pull classified information from a person’s c
Securelist
Investigation Report for the September 2014 Equation malware detection incident in the US
blogs_securelist·2017-11-16
Investigation Report for the September 2014 Equation malware detection incident in the US
Authors
Kaspersky
## Background
In early October, a story was published by the Wall Street Journal alleging Kaspersky Lab software was used to siphon classified data from an NSA employee’s home computer system. Given that Kaspersky Lab has been at the forefront of fighting cyberespionage and cybercriminal activities on the Internet for over 20 years now, these allegations were treated very seriously. To assist any independent investigators and all the people who have been asking us questions whether those allegations were true, we decided to conduct an internal investigation to attempt to answer a few questions we had related to the article and some others that followed it:
Was our software used outside of its intended functionality to pull classified information from a person’s comput
http://java.sun.com/javase/6/webnotes/6u17.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.htmlhttp://marc.info/?l=bugtraq&m=126566824131534&w=2http://marc.info/?l=bugtraq&m=131593453929393&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/37231http://secunia.com/advisories/37239http://secunia.com/advisories/37386http://secunia.com/advisories/37581http://secunia.com/advisories/37841http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://securitytracker.com/id?1023132http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1http://support.apple.com/kb/HT3969http://support.apple.com/kb/HT3970http://www.mandriva.com/security/advisories?name=MDVSA-2010:084http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1694.htmlhttp://www.securityfocus.com/bid/36881http://www.vupen.com/english/advisories/2009/3131http://zerodayinitiative.com/advisories/ZDI-09-078/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10741https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11262https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7400https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8566http://java.sun.com/javase/6/webnotes/6u17.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.htmlhttp://marc.info/?l=bugtraq&m=126566824131534&w=2http://marc.info/?l=bugtraq&m=131593453929393&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/37231http://secunia.com/advisories/37239http://secunia.com/advisories/37386http://secunia.com/advisories/37581http://secunia.com/advisories/37841http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://securitytracker.com/id?1023132http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1http://support.apple.com/kb/HT3969http://support.apple.com/kb/HT3970http://www.mandriva.com/security/advisories?name=MDVSA-2010:084http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1694.htmlhttp://www.securityfocus.com/bid/36881http://www.vupen.com/english/advisories/2009/3131http://zerodayinitiative.com/advisories/ZDI-09-078/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10741https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11262https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7400https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8566
2009-11-05
Published