First published: Wed Aug 05 2009(Updated: )
Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old version of JNLPAppletLauncher.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java SE | ||
Sun Java SE | ||
OpenJDK | <=1.5.0 | |
OpenJDK | <=1.6.0 | |
OpenJDK | =1.5.0 | |
OpenJDK | =1.5.0-update1 | |
OpenJDK | =1.5.0-update10 | |
OpenJDK | =1.5.0-update11 | |
OpenJDK | =1.5.0-update11_b03 | |
OpenJDK | =1.5.0-update12 | |
OpenJDK | =1.5.0-update13 | |
OpenJDK | =1.5.0-update14 | |
OpenJDK | =1.5.0-update15 | |
OpenJDK | =1.5.0-update16 | |
OpenJDK | =1.5.0-update17 | |
OpenJDK | =1.5.0-update18 | |
OpenJDK | =1.5.0-update2 | |
OpenJDK | =1.5.0-update3 | |
OpenJDK | =1.5.0-update4 | |
OpenJDK | =1.5.0-update5 | |
OpenJDK | =1.5.0-update6 | |
OpenJDK | =1.5.0-update7 | |
OpenJDK | =1.5.0-update8 | |
OpenJDK | =1.5.0-update9 | |
OpenJDK | =1.6.0-update_10 | |
OpenJDK | =1.6.0-update_11 | |
OpenJDK | =1.6.0-update_12 | |
OpenJDK | =1.6.0-update_13 | |
OpenJDK | =1.6.0-update_3 | |
OpenJDK | =1.6.0-update_4 | |
OpenJDK | =1.6.0-update_5 | |
OpenJDK | =1.6.0-update_6 | |
OpenJDK | =1.6.0-update_7 | |
OpenJDK | =1.6.0-update1 | |
OpenJDK | =1.6.0-update2 | |
Sun JRE | <=1.5.0 | |
Sun JRE | <=1.6.0 | |
Sun JRE | =1.5.0 | |
Sun JRE | =1.5.0-update1 | |
Sun JRE | =1.5.0-update10 | |
Sun JRE | =1.5.0-update11 | |
Sun JRE | =1.5.0-update12 | |
Sun JRE | =1.5.0-update13 | |
Sun JRE | =1.5.0-update14 | |
Sun JRE | =1.5.0-update15 | |
Sun JRE | =1.5.0-update16 | |
Sun JRE | =1.5.0-update17 | |
Sun JRE | =1.5.0-update18 | |
Sun JRE | =1.5.0-update2 | |
Sun JRE | =1.5.0-update3 | |
Sun JRE | =1.5.0-update4 | |
Sun JRE | =1.5.0-update5 | |
Sun JRE | =1.5.0-update6 | |
Sun JRE | =1.5.0-update7 | |
Sun JRE | =1.5.0-update8 | |
Sun JRE | =1.5.0-update9 | |
Sun JRE | =1.6.0-update_1 | |
Sun JRE | =1.6.0-update_10 | |
Sun JRE | =1.6.0-update_11 | |
Sun JRE | =1.6.0-update_12 | |
Sun JRE | =1.6.0-update_13 | |
Sun JRE | =1.6.0-update_2 | |
Sun JRE | =1.6.0-update_3 | |
Sun JRE | =1.6.0-update_4 | |
Sun JRE | =1.6.0-update_5 | |
Sun JRE | =1.6.0-update_6 | |
Sun JRE | =1.6.0-update_7 | |
Sun JRE | <=1.4.2_21 | |
Sun JRE | =1.4.0 | |
Sun JRE | =1.4.0_01 | |
Sun JRE | =1.4.0_02 | |
Sun JRE | =1.4.0_03 | |
Sun JRE | =1.4.0_04 | |
Sun JRE | =1.4.1 | |
Sun JRE | =1.4.1-update1 | |
Sun JRE | =1.4.1-update2 | |
Sun JRE | =1.4.1-update3 | |
Sun JRE | =1.4.1-update4 | |
Sun JRE | =1.4.1-update5 | |
Sun JRE | =1.4.1-update6 | |
Sun JRE | =1.4.1-update7 | |
Sun JRE | =1.4.2 | |
Sun JRE | =1.4.2-update16 | |
Sun JRE | =1.4.2-update17 | |
Sun JRE | =1.4.2-update18 | |
Sun JRE | =1.4.2-update19 | |
Sun JRE | =1.4.2-update20 | |
Sun JRE | =1.4.2_1 | |
Sun JRE | =1.4.2_2 | |
Sun JRE | =1.4.2_3 | |
Sun JRE | =1.4.2_4 | |
Sun JRE | =1.4.2_5 | |
Sun JRE | =1.4.2_6 | |
Sun JRE | =1.4.2_7 | |
Sun JRE | =1.4.2_8 | |
Sun JRE | =1.4.2_9 | |
Sun JRE | =1.4.2_10 | |
Sun JRE | =1.4.2_11 | |
Sun JRE | =1.4.2_12 | |
Sun JRE | =1.4.2_13 | |
Sun JRE | =1.4.2_14 | |
Sun JRE | =1.4.2_15 | |
Sun SDK | <=1.4.2_21 | |
Sun SDK | =1.4.0 | |
Sun SDK | =1.4.0_01 | |
Sun SDK | =1.4.0_02 | |
Sun SDK | =1.4.0_03 | |
Sun SDK | =1.4.0_04 | |
Sun SDK | =1.4.1 | |
Sun SDK | =1.4.1_01 | |
Sun SDK | =1.4.1_02 | |
Sun SDK | =1.4.1_03 | |
Sun SDK | =1.4.1_04 | |
Sun SDK | =1.4.1_05 | |
Sun SDK | =1.4.1_06 | |
Sun SDK | =1.4.1_07 | |
Sun SDK | =1.4.2 | |
Sun SDK | =1.4.2_1 | |
Sun SDK | =1.4.2_2 | |
Sun SDK | =1.4.2_3 | |
Sun SDK | =1.4.2_4 | |
Sun SDK | =1.4.2_5 | |
Sun SDK | =1.4.2_6 | |
Sun SDK | =1.4.2_7 | |
Sun SDK | =1.4.2_8 | |
Sun SDK | =1.4.2_9 | |
Sun SDK | =1.4.2_10 | |
Sun SDK | =1.4.2_11 | |
Sun SDK | =1.4.2_12 | |
Sun SDK | =1.4.2_13 | |
Sun SDK | =1.4.2_14 | |
Sun SDK | =1.4.2_15 | |
Sun SDK | =1.4.2_16 | |
Sun SDK | =1.4.2_17 | |
Sun SDK | =1.4.2_18 | |
Sun SDK | =1.4.2_19 | |
Sun SDK | =1.4.2_20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2009-2676 vulnerability is classified as high severity due to its potential to allow remote attackers to create or modify arbitrary files.
To mitigate CVE-2009-2676, update Sun Java SE to a version later than JDK and JRE 6 Update 14 or JDK and JRE 5.0 Update 19.
CVE-2009-2676 affects multiple versions of Sun Java SE, JDK, and JRE including versions up to 6 Update 14 and 5.0 Update 19.
Exploitation of CVE-2009-2676 could lead to unauthorized file creation or modification on affected systems.
CVE-2009-2676 can be exploited by remote attackers, making it critical for users to apply security patches promptly.