CVE-2009-1719: Code Injection
The Aqua Look and Feel for Java implementation in Java 1.5 on Mac OS X 10.5 allows remote attackers to execute arbitrary code via a call to the undocumented apple.laf.CColourUIResource constructor with a crafted value in the first argument, which is dereferenced as a pointer.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1719?
CVE-2009-1719 has a high severity rating due to its ability to allow remote code execution.
How do I fix CVE-2009-1719?
To fix CVE-2009-1719, update your Apple Mac OS X or Java Runtime Environment to the latest versions that contain security patches.
Which software versions are affected by CVE-2009-1719?
CVE-2009-1719 affects Java 1.5 on Mac OS X 10.5 and its updates.
Can CVE-2009-1719 be exploited remotely?
Yes, CVE-2009-1719 can be exploited remotely through the use of a crafted method call.
What is the impact of CVE-2009-1719 on my system?
The impact of CVE-2009-1719 includes the potential for an attacker to execute arbitrary code on the affected system.