First published: Wed Aug 05 2009(Updated: )
Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun JDK | =5.0-update_12 | |
Sun JDK | =5.0-update_15 | |
Sun JRE | =5.0-update_19 | |
Sun JDK | =5.0-update_3 | |
Sun JRE | =5.0-update_13 | |
Sun JRE | =5.0-update_1 | |
Sun JDK | =5.0-update_11 | |
Sun JRE | =6-update_10 | |
Sun JRE | <=6 | |
Sun JDK | =6-update_6 | |
Sun JDK | =6-update_7 | |
Sun JDK | =5.0-update_8 | |
Sun JRE | =5.0-update_14 | |
Sun JRE | =6-update_3 | |
Sun JDK | =6-update_11 | |
Sun JRE | =6-update_4 | |
Sun JRE | =5.0-update_12 | |
Sun JDK | =5.0-update_1 | |
Sun JDK | =5.0-update_17 | |
Sun JDK | =6-update_1 | |
Sun JDK | =6-update_3 | |
Sun JDK | =6-update_9 | |
Sun JDK | =5.0-update_5 | |
Sun JRE | =6-update_2 | |
Sun JRE | =5.0-update_4 | |
Sun JRE | =6-update_9 | |
Sun JDK | =6-update_4 | |
Sun JDK | =6-update_12 | |
Sun JDK | <=6 | |
Sun JRE | =5.0-update_9 | |
Sun JRE | =5.0-update_8 | |
Sun JRE | =5.0-update_7 | |
Sun JDK | =5.0-update_6 | |
Sun JRE | =5.0-update_15 | |
Sun JRE | =6-update_11 | |
Sun JRE | =6-update_5 | |
Sun JRE | =5.0-update_16 | |
Sun JDK | =5.0-update_14 | |
Sun JDK | =6-update_8 | |
Sun JRE | =6-update_12 | |
Sun JRE | =5.0-update_2 | |
Sun JDK | =6-update_2 | |
Sun JRE | =6-update_7 | |
Sun JRE | =6-update_8 | |
Sun JDK | =5.0-update_13 | |
Sun JRE | =5.0-update_5 | |
Sun JDK | =5.0-update_16 | |
Sun JRE | =5.0-update_6 | |
Sun JRE | =5.0-update_11 | |
Sun JRE | =6-update_1 | |
Sun JDK | =6-update_5 | |
Sun JRE | =5.0-update_17 | |
Sun JDK | =5.0-update_10 | |
Sun JDK | =5.0-update_2 | |
Sun JDK | =5.0-update_4 | |
Sun JDK | =5.0-update_9 | |
Sun JRE | =6-update_6 | |
Sun JRE | =5.0-update_3 | |
Sun JRE | =5.0-update_10 | |
Sun JDK | =5.0-update_7 | |
Sun JDK | =6-update_10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2675 has a medium severity rating, which may allow attackers to execute arbitrary code under certain conditions.
To fix CVE-2009-2675, upgrade to the latest version of the Sun Java Runtime Environment that addresses this vulnerability.
CVE-2009-2675 affects Sun JDK and JRE 5.0 before Update 20 and JDK and JRE 6 before Update 15.
Exploiting CVE-2009-2675 can allow privileged execution of arbitrary code, potentially leading to full system compromise.
Any user or organization utilizing affected versions of the Sun JDK or JRE is at risk for CVE-2009-2675.