CVE-2009-3884
published 2009-11-09CVE-2009-3884: The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of…
PriorityP425medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.95%
85.6th percentile
The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jre | <= 1.5.0 | — |
| sun | jre | <= 1.6.0 | — |
| sun | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_ubuntu5.1MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2009-11-12·CVSS 5.1
CVE-2009-3728 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: OpenJDK vulnerabilities
Dan Kaminsky discovered that SSL certificates signed with MD2 could be
spoofed given enough time. As a result, an attacker could potentially
create a malicious trusted certificate to impersonate another site. This
update handles this issue by completely disabling MD2 for certificate
validation in OpenJDK. (CVE-2009-2409)
It was discovered that ICC profiles could be identified with
".." pathnames. If a user were tricked into running a specially
crafted applet, a remote attacker could gain information about a local
system. (CVE-2009-3728)
Peter Vreugdenhil discovered multiple flaws in the processing of graphics
in the AWT library. If a user were tricked into running a specially
crafted applet, a remote attacker could crash t
Red Hat
OpenJDK zoneinfo file existence information leak (6824265)
vendor_redhat·2009-11-03·CVSS 5.0
CVE-2009-3884 [MEDIUM] OpenJDK zoneinfo file existence information leak (6824265)
OpenJDK zoneinfo file existence information leak (6824265)
The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.
GHSA
GHSA-pc3p-mx4p-7j4f: The TimeZone
ghsa_unreviewed·2022-05-02
CVE-2009-3884 [MEDIUM] GHSA-pc3p-mx4p-7j4f: The TimeZone
The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.
No detection rules found.
http://java.sun.com/j2se/1.5.0/ReleaseNotes.htmlhttp://java.sun.com/javase/6/webnotes/6u17.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00001.htmlhttp://secunia.com/advisories/37386http://secunia.com/advisories/37581http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://support.apple.com/kb/HT3969http://support.apple.com/kb/HT3970http://www.mandriva.com/security/advisories?name=MDVSA-2010:084https://bugzilla.redhat.com/show_bug.cgi?id=530300https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11686https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6960http://java.sun.com/j2se/1.5.0/ReleaseNotes.htmlhttp://java.sun.com/javase/6/webnotes/6u17.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00001.htmlhttp://secunia.com/advisories/37386http://secunia.com/advisories/37581http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://support.apple.com/kb/HT3969http://support.apple.com/kb/HT3970http://www.mandriva.com/security/advisories?name=MDVSA-2010:084https://bugzilla.redhat.com/show_bug.cgi?id=530300https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11686https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6960
2009-11-09
Published