CVE-2009-1100: Medium severity Java Development Kit (JDK) vulnerability
Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attackers to cause a denial of service (disk consumption) via vectors related to temporary font files and (1) "limits on Font creation," aka CR 6522586, and (2) another unspecified vector, aka CR 6632886.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Enforce disk quotas and monitoring/alerting on temporary directories used by Java processes, and isolate Java processes' temporary directories where possible, to prevent disk exhaustion from temporary font files (as observed in JDK and JRE 5.0 Update 17 and earlier, and 6 Update 12 and earlier).
- Operational
Locate and remove temporary font files created by affected Java installations (JDK and JRE 5.0 Update 17 and earlier, and 6 Update 12 and earlier) to free disk space and mitigate ongoing disk-consumption denial-of-service.
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1100?
CVE-2009-1100 has a severity rating that allows remote attackers to potentially cause a denial of service through disk consumption.
How do I fix CVE-2009-1100?
To fix CVE-2009-1100, users should update their Java SE Development Kit and Java Runtime Environment to the latest available versions.
What software is affected by CVE-2009-1100?
CVE-2009-1100 affects Java SE Development Kit (JDK) and Java Runtime Environment (JRE) versions 5.0 Update 17 and earlier, and 6 Update 12 and earlier.
How can CVE-2009-1100 be exploited?
CVE-2009-1100 can be exploited by remote attackers through vectors related to temporary font files, leading to potential denial of service.
Is there a workaround for CVE-2009-1100?
A temporary workaround for CVE-2009-1100 may involve limiting the application of fonts or using older versions of Java that are not affected.