CVE-2009-1097: Buffer Overflow
Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1097?
CVE-2009-1097 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2009-1097?
To fix CVE-2009-1097, users should upgrade to a patched version of the Java SE Development Kit or Java Runtime Environment provided by Oracle or adopt the latest Java versions.
Which versions of software are affected by CVE-2009-1097?
CVE-2009-1097 affects Java SE Development Kit (JDK) and Java Runtime Environment (JRE) version 6 Update 12 and earlier.
Can CVE-2009-1097 lead to data breaches?
Yes, CVE-2009-1097 can lead to data breaches as it allows attackers to access files on affected systems.
What kind of attacks can exploit CVE-2009-1097?
CVE-2009-1097 can be exploited through crafted PNG images, which cause buffer overflows leading to potential code execution.