CVE-2009-2719: Buffer Overflow
The Java Web Start implementation in Sun Java SE 6 before Update 15 allows context-dependent attackers to cause a denial of service (NullPointerException) via a crafted .jnlp file, as demonstrated by the jnlpfile/appletDesc/index.html#misc test in the Technology Compatibility Kit (TCK) for the Java Network Launching Protocol (JNLP).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2719?
CVE-2009-2719 is classified as a moderate severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2009-2719?
To fix CVE-2009-2719, update your Sun Java SE to version 6 Update 15 or later.
What type of attack does CVE-2009-2719 facilitate?
CVE-2009-2719 allows context-dependent attackers to cause a denial of service by triggering a NullPointerException.
Which software versions are affected by CVE-2009-2719?
CVE-2009-2719 affects Java SE 6 versions prior to Update 15.
What exploit method is associated with CVE-2009-2719?
The exploit method associated with CVE-2009-2719 involves the use of a crafted .jnlp file.