CVE-2009-3728: Path Traversal
Directory traversal vulnerability in the ICCProfile.getInstance method in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local International Color Consortium (ICC) profile files via a .. (dot dot) in a pathname, aka Bug Id 6631533.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3728?
CVE-2009-3728 has a high severity rating due to its potential to allow remote attackers to access and determine local file paths.
How do I fix CVE-2009-3728?
To mitigate CVE-2009-3728, upgrade to the latest version of the Java Runtime Environment or apply the recommended patches for affected versions.
Which versions are affected by CVE-2009-3728?
CVE-2009-3728 affects Sun Java SE 5.0 before Update 22 and 6 before Update 17, along with certain versions of OpenJDK.
What kind of attacks can exploit CVE-2009-3728?
CVE-2009-3728 can be exploited by remote attackers to perform directory traversal attacks, potentially exposing sensitive file information.
Is there a workaround for CVE-2009-3728 if I cannot update?
A potential workaround for CVE-2009-3728 includes restricting access to the affected file areas while planning for a proper upgrade.