CVE-2009-3875
published 2009-11-05CVE-2009-3875: The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK…
PriorityP432medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
3.11%
86.2th percentile
The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to "timing attack vulnerabilities," aka Bug Id 6863503.
Affected
137 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | bea_product_suite | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_ubuntu5.1MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2009-11-12·CVSS 5.1
CVE-2009-3728 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: OpenJDK vulnerabilities
Dan Kaminsky discovered that SSL certificates signed with MD2 could be
spoofed given enough time. As a result, an attacker could potentially
create a malicious trusted certificate to impersonate another site. This
update handles this issue by completely disabling MD2 for certificate
validation in OpenJDK. (CVE-2009-2409)
It was discovered that ICC profiles could be identified with
".." pathnames. If a user were tricked into running a specially
crafted applet, a remote attacker could gain information about a local
system. (CVE-2009-3728)
Peter Vreugdenhil discovered multiple flaws in the processing of graphics
in the AWT library. If a user were tricked into running a specially
crafted applet, a remote attacker could crash t
Red Hat
OpenJDK MessageDigest.isEqual introduces timing attack vulnerabilities (6863503)
vendor_redhat·2009-11-03·CVSS 5.0
CVE-2009-3875 [MEDIUM] OpenJDK MessageDigest.isEqual introduces timing attack vulnerabilities (6863503)
OpenJDK MessageDigest.isEqual introduces timing attack vulnerabilities (6863503)
The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to "timing attack vulnerabilities," aka Bug Id 6863503.
GHSA
GHSA-3524-9jx8-82v5: Multiple vulnerabilities in the JRockit component in BEA Product Suite R27
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2010-0079 [CRITICAL] GHSA-3524-9jx8-82v5: Multiple vulnerabilities in the JRockit component in BEA Product Suite R27
Multiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2, 5, and 6 allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this CVE identifier overlaps CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, and CVE-2009-3877.
GHSA
GHSA-p88x-7ffg-vgpw: The MessageDigest
ghsa_unreviewed·2022-05-02
CVE-2009-3875 [MEDIUM] GHSA-p88x-7ffg-vgpw: The MessageDigest
The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to "timing attack vulnerabilities," aka Bug Id 6863503.
No detection rules found.
No public exploits indexed.
http://java.sun.com/javase/6/webnotes/6u17.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.htmlhttp://marc.info/?l=bugtraq&m=126566824131534&w=2http://marc.info/?l=bugtraq&m=131593453929393&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/37231http://secunia.com/advisories/37239http://secunia.com/advisories/37386http://secunia.com/advisories/37581http://secunia.com/advisories/37841http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-270475-1http://support.apple.com/kb/HT3969http://support.apple.com/kb/HT3970http://www.mandriva.com/security/advisories?name=MDVSA-2010:084http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1694.htmlhttp://www.securityfocus.com/bid/36881http://www.vupen.com/english/advisories/2009/3131https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11847https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12112https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7549https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7913http://java.sun.com/javase/6/webnotes/6u17.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.htmlhttp://marc.info/?l=bugtraq&m=126566824131534&w=2http://marc.info/?l=bugtraq&m=131593453929393&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/37231http://secunia.com/advisories/37239http://secunia.com/advisories/37386http://secunia.com/advisories/37581http://secunia.com/advisories/37841http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-270475-1http://support.apple.com/kb/HT3969http://support.apple.com/kb/HT3970http://www.mandriva.com/security/advisories?name=MDVSA-2010:084http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1694.htmlhttp://www.securityfocus.com/bid/36881http://www.vupen.com/english/advisories/2009/3131https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11847https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12112https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7549https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7913
2009-11-05
Published