CVE-2009-1094: Critical severity Sun JDK vulnerability
Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.124 and earlier; and 1.4.219 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.13-1jpp.1.el4 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.5.0-sun-0:1.5.0.18-1jpp.1.el4 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.5.0-ibm-1:1.5.0.9-1jpp.5.el4 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.5-1jpp.1.el4 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-openjdk-1:1.6.0.0-0.30.b09.el5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.5.0-sun-0:1.5.0.22-1jpp.1.el4 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.7-1jpp.3.el4 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.13-1jpp.1.el5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.5.0-sun-0:1.5.0.18-1jpp.1.el5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.5.0-ibm-1:1.5.0.9-1jpp.3.el5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.5-1jpp.1.el5
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2009-1094?
CVE-2009-1094 is considered to have a high severity due to its potential to allow remote LDAP servers to execute arbitrary code.
How do I fix CVE-2009-1094?
To fix CVE-2009-1094, you should update to a patched version of the Java SE Development Kit or Java Runtime Environment provided by your vendor.
Which versions are affected by CVE-2009-1094?
CVE-2009-1094 affects Java SE Development Kit (JDK) and Java Runtime Environment (JRE) versions 1.5.0 through 1.6.0 update 12 and earlier.
Can CVE-2009-1094 be exploited remotely?
Yes, CVE-2009-1094 can be exploited remotely by an attacker using malicious LDAP inputs to execute arbitrary code on the affected system.
What precautions should I take to prevent CVE-2009-1094 exploitation?
To prevent exploitation of CVE-2009-1094, ensure that you apply security updates and patches from your Java vendor promptly.