CVE-2009-3873
published 2009-11-05CVE-2009-3873: The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote…
PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.21%
89.8th percentile
The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.
Affected
136 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | bea_product_suite | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2009-11-12·CVSS 5.1
CVE-2009-3728 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: OpenJDK vulnerabilities
Dan Kaminsky discovered that SSL certificates signed with MD2 could be
spoofed given enough time. As a result, an attacker could potentially
create a malicious trusted certificate to impersonate another site. This
update handles this issue by completely disabling MD2 for certificate
validation in OpenJDK. (CVE-2009-2409)
It was discovered that ICC profiles could be identified with
".." pathnames. If a user were tricked into running a specially
crafted applet, a remote attacker could gain information about a local
system. (CVE-2009-3728)
Peter Vreugdenhil discovered multiple flaws in the processing of graphics
in the AWT library. If a user were tricked into running a specially
crafted applet, a remote attacker could crash t
Red Hat
OpenJDK JPEG Image Writer quantization problem (6862968)
vendor_redhat·2009-11-03·CVSS 9.3
CVE-2009-3873 [CRITICAL] OpenJDK JPEG Image Writer quantization problem (6862968)
OpenJDK JPEG Image Writer quantization problem (6862968)
The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.
GHSA
GHSA-3524-9jx8-82v5: Multiple vulnerabilities in the JRockit component in BEA Product Suite R27
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2010-0079 [CRITICAL] GHSA-3524-9jx8-82v5: Multiple vulnerabilities in the JRockit component in BEA Product Suite R27
Multiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2, 5, and 6 allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this CVE identifier overlaps CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, and CVE-2009-3877.
GHSA
GHSA-jgrv-c256-j463: The JPEG Image Writer in Sun Java SE in JDK and JRE 5
ghsa_unreviewed·2022-05-02
CVE-2009-3873 [HIGH] CWE-119 GHSA-jgrv-c256-j463: The JPEG Image Writer in Sun Java SE in JDK and JRE 5
The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3873 OpenJDK JPEG Image Writer quantization problem (6862968)
bugzilla·2009-10-21·CVSS 9.3
CVE-2009-3873 [CRITICAL] CVE-2009-3873 OpenJDK JPEG Image Writer quantization problem (6862968)
CVE-2009-3873 OpenJDK JPEG Image Writer quantization problem (6862968)
A buffer overflow vulnerability in the Java Runtime Environment
with processing JPEG files may allow an untrusted applet or Java Web Start
application to escalate privileges. For example, an untrusted applet
may grant itself permissions to read and write local files or
execute local applications that are accessible to the user
running the untrusted applet.
Discussion:
*** Bug 533225 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2009:1560 https://rhn.redhat.com/errata/RHSA-2009-1560.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterpris
arXiv
The Effect of Security Education and Expertise on Security Assessments: the Case of Software Vulnerabilities
arxiv_fulltext·2018-08-20
The Effect of Security Education and Expertise on Security Assessments: the Case of Software Vulnerabilities
The Effect of Security Education and Expertise on Security Assessments: the Case of Software Vulnerabilities
Luca Allodi,
Marco Cremonini,
Fabio Massacci,
Woohyun Shim
L. Allodi is at the Eindhoven Univ.\ of Technology, NL. ([email protected]).
M. Cremonini is at the Univ.\ of Milan, IT. [email protected].
Fabio Massacci is at the Univ.\ of Trento,IT. [email protected].
W. Shim is with the Korea Institute of Public Administration, KR.
## Abstract
In spite of the growing importance of software security and the industry demand for more cyber security expertise in the workforce, the effect of security education and experience on the ability to assess complex software security problems has only been recently investigated.
As proxy for the full range of software security skills,
http://java.sun.com/javase/6/webnotes/6u17.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.htmlhttp://marc.info/?l=bugtraq&m=126566824131534&w=2http://marc.info/?l=bugtraq&m=131593453929393&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/37231http://secunia.com/advisories/37239http://secunia.com/advisories/37386http://secunia.com/advisories/37581http://secunia.com/advisories/37841http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://securitytracker.com/id?1023132http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1http://support.apple.com/kb/HT3969http://support.apple.com/kb/HT3970http://www.mandriva.com/security/advisories?name=MDVSA-2010:084http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1694.htmlhttp://www.securityfocus.com/bid/36881http://www.vupen.com/english/advisories/2009/3131https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11746https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6970https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8396https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9602http://java.sun.com/javase/6/webnotes/6u17.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.htmlhttp://marc.info/?l=bugtraq&m=126566824131534&w=2http://marc.info/?l=bugtraq&m=131593453929393&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/37231http://secunia.com/advisories/37239http://secunia.com/advisories/37386http://secunia.com/advisories/37581http://secunia.com/advisories/37841http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://securitytracker.com/id?1023132http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1http://support.apple.com/kb/HT3969http://support.apple.com/kb/HT3970http://www.mandriva.com/security/advisories?name=MDVSA-2010:084http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1694.htmlhttp://www.securityfocus.com/bid/36881http://www.vupen.com/english/advisories/2009/3131https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11746https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6970https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8396https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9602
2009-11-05
Published