First published: Thu Nov 05 2009(Updated: )
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun JDK | =1.5.0-update_9 | |
Sun JDK | =1.6.0-update_4 | |
Sun JRE | =1.6.0-update_3 | |
Sun JRE | =1.5.0-update_14 | |
Sun JRE | =1.6.0-update_5 | |
Sun JDK | =1.6.0-update_7 | |
Sun JDK | =1.5.0-update_15 | |
Sun JDK | =1.5.0-update_19 | |
Sun JRE | =1.5.0-update_13 | |
Sun JDK | =1.6.0-update_13 | |
Sun JRE | =1.5.0-update_21 | |
Sun JRE | =1.5.0-update_6 | |
Sun JRE | =1.5.0-update_11 | |
Sun JRE | =1.6.0-update_13 | |
Sun JRE | =1.5.0-update_12 | |
Sun JDK | =1.6.0-update_9 | |
Sun JDK | =1.5.0-update_18 | |
Sun JRE | =1.6.0-update_1 | |
Sun JRE | =1.6.0-update_2 | |
Sun JDK | =1.6.0-update_3 | |
Sun JRE | =1.6.0-update_16 | |
Sun JDK | =1.6.0-update_11 | |
Sun JDK | =1.6.0-update_10 | |
Sun JRE | =1.6.0-update_15 | |
Sun JDK | =1.5.0-update_10 | |
Sun JRE | =1.5.0-update_15 | |
Sun JRE | =1.5.0-update_5 | |
Sun JDK | =1.5.0-update_5 | |
Sun JRE | =1.6.0-update_6 | |
Sun JDK | =1.6.0-update_14 | |
Sun JDK | =1.5.0-update_1 | |
Sun JRE | =1.5.0-update_3 | |
Sun JRE | =1.5.0-update_19 | |
Sun JDK | =1.5.0-update_17 | |
Sun JRE | =1.5.0-update_16 | |
Sun JDK | =1.5.0-update_6 | |
Sun JDK | =1.6.0-update_5 | |
Sun JDK | =1.5.0-update_20 | |
Sun JDK | =1.6.0-update_8 | |
Sun JDK | =1.5.0-update_13 | |
Sun JRE | =1.6.0-update_10 | |
Sun JRE | =1.5.0-update_2 | |
Sun JRE | =1.5.0-update_18 | |
Sun JRE | =1.5.0-update_20 | |
Sun JDK | =1.6.0-update_16 | |
Sun JRE | =1.6.0-update_8 | |
Sun JDK | =1.5.0-update_16 | |
Sun JDK | =1.5.0-update_4 | |
Sun JRE | =1.5.0-update_8 | |
Sun JDK | =1.5.0-update_3 | |
Sun JRE | =1.5.0-update_1 | |
Sun JRE | =1.5.0-update_17 | |
Sun JDK | =1.5.0-update_12 | |
Sun JRE | =1.5.0-update_4 | |
Sun JDK | =1.5.0-update_7 | |
Sun JDK | =1.5.0-update_21 | |
Sun JRE | =1.6.0-update_7 | |
Sun JRE | =1.6.0-update_14 | |
Sun JDK | =1.5.0-update_11 | |
Sun JDK | =1.6.0-update_15 | |
Sun JDK | =1.6.0-update_12 | |
Sun JRE | =1.5.0-update_7 | |
Sun JRE | =1.6.0-update_4 | |
Sun JRE | =1.5.0-update_9 | |
Sun JDK | =1.6.0-update_1 | |
Sun JDK | =1.6.0-update_6 | |
Sun JRE | =1.6.0-update_9 | |
Sun JRE | =1.6.0-update_12 | |
Sun JDK | =1.5.0-update_14 | |
Sun JDK | =1.5.0-update_8 | |
Sun JDK | =1.5.0-update_2 | |
Sun JRE | =1.6.0-update_11 | |
Sun JRE | =1.4.2_1 | |
Sun JRE | =1.4.2_2 | |
Sun JRE | =1.4.2_02 | |
Sun JRE | =1.4.2_03 | |
Sun JRE | =1.4.2_3 | |
Sun JRE | =1.4.2_4 | |
Sun JRE | =1.4.2_04 | |
Sun JRE | =1.4.2_05 | |
Sun JRE | =1.4.2_5 | |
Sun JRE | =1.4.2_06 | |
Sun JRE | =1.4.2_6 | |
Sun JRE | =1.4.2_7 | |
Sun JRE | =1.4.2_07 | |
Sun JRE | =1.4.2_8 | |
Sun JRE | =1.4.2_08 | |
Sun JRE | =1.4.2_09 | |
Sun JRE | =1.4.2_9 | |
Sun JRE | =1.4.2_10 | |
Sun JRE | =1.4.2_11 | |
Sun JRE | =1.4.2_12 | |
Sun JRE | =1.4.2_13 | |
Sun JRE | =1.4.2_14 | |
Sun JRE | =1.4.2_15 | |
Sun JRE | =1.4.2_16 | |
Sun JRE | =1.4.2_17 | |
Sun JRE | =1.4.2_18 | |
Sun JRE | =1.4.2_19 | |
Sun JRE | =1.4.2_20 | |
Sun JRE | =1.4.2_21 | |
Sun JRE | =1.4.2_22 | |
Sun SDK | =1.4.2_01 | |
Sun SDK | =1.4.2_1 | |
Sun SDK | =1.4.2_2 | |
Sun SDK | =1.4.2_02 | |
Sun SDK | =1.4.2_03 | |
Sun SDK | =1.4.2_3 | |
Sun SDK | =1.4.2_04 | |
Sun SDK | =1.4.2_4 | |
Sun SDK | =1.4.2_5 | |
Sun SDK | =1.4.2_05 | |
Sun SDK | =1.4.2_6 | |
Sun SDK | =1.4.2_06 | |
Sun SDK | =1.4.2_07 | |
Sun SDK | =1.4.2_7 | |
Sun SDK | =1.4.2_8 | |
Sun SDK | =1.4.2_08 | |
Sun SDK | =1.4.2_09 | |
Sun SDK | =1.4.2_9 | |
Sun SDK | =1.4.2_10 | |
Sun SDK | =1.4.2_11 | |
Sun SDK | =1.4.2_12 | |
Sun SDK | =1.4.2_13 | |
Sun SDK | =1.4.2_14 | |
Sun SDK | =1.4.2_15 | |
Sun SDK | =1.4.2_16 | |
Sun SDK | =1.4.2_17 | |
Sun SDK | =1.4.2_18 | |
Sun SDK | =1.4.2_19 | |
Sun SDK | =1.4.2_20 | |
Sun SDK | =1.4.2_21 | |
Sun SDK | =1.4.2_22 | |
Oracle Solaris SPARC | ||
Sun JRE | =1.3.1_1 | |
Sun JRE | =1.3.1_01 | |
Sun JRE | =1.3.1_01a | |
Sun JRE | =1.3.1_02 | |
Sun JRE | =1.3.1_2 | |
Sun JRE | =1.3.1_03 | |
Sun JRE | =1.3.1_3 | |
Sun JRE | =1.3.1_4 | |
Sun JRE | =1.3.1_04 | |
Sun JRE | =1.3.1_05 | |
Sun JRE | =1.3.1_5 | |
Sun JRE | =1.3.1_06 | |
Sun JRE | =1.3.1_6 | |
Sun JRE | =1.3.1_07 | |
Sun JRE | =1.3.1_7 | |
Sun JRE | =1.3.1_8 | |
Sun JRE | =1.3.1_08 | |
Sun JRE | =1.3.1_9 | |
Sun JRE | =1.3.1_09 | |
Sun JRE | =1.3.1_10 | |
Sun JRE | =1.3.1_11 | |
Sun JRE | =1.3.1_12 | |
Sun JRE | =1.3.1_13 | |
Sun JRE | =1.3.1_14 | |
Sun JRE | =1.3.1_15 | |
Sun JRE | =1.3.1_16 | |
Sun JRE | =1.3.1_17 | |
Sun JRE | =1.3.1_18 | |
Sun JRE | =1.3.1_19 | |
Sun JRE | =1.3.1_20 | |
Sun JRE | =1.3.1_21 | |
Sun JRE | =1.3.1_22 | |
Sun JRE | =1.3.1_23 | |
Sun JRE | =1.3.1_24 | |
Sun JRE | =1.3.1_25 | |
Sun SDK | =1.3.1_01 | |
Sun SDK | =1.3.1_01a | |
Sun SDK | =1.3.1_2 | |
Sun SDK | =1.3.1_02 | |
Sun SDK | =1.3.1_03 | |
Sun SDK | =1.3.1_3 | |
Sun SDK | =1.3.1_4 | |
Sun SDK | =1.3.1_04 | |
Sun SDK | =1.3.1_5 | |
Sun SDK | =1.3.1_05 | |
Sun SDK | =1.3.1_6 | |
Sun SDK | =1.3.1_06 | |
Sun SDK | =1.3.1_7 | |
Sun SDK | =1.3.1_07 | |
Sun SDK | =1.3.1_8 | |
Sun SDK | =1.3.1_08 | |
Sun SDK | =1.3.1_9 | |
Sun SDK | =1.3.1_09 | |
Sun SDK | =1.3.1_10 | |
Sun SDK | =1.3.1_11 | |
Sun SDK | =1.3.1_12 | |
Sun SDK | =1.3.1_13 | |
Sun SDK | =1.3.1_14 | |
Sun SDK | =1.3.1_15 | |
Sun SDK | =1.3.1_16 | |
Sun SDK | =1.3.1_17 | |
Sun SDK | =1.3.1_18 | |
Sun SDK | =1.3.1_19 | |
Sun SDK | =1.3.1_20 | |
Sun SDK | =1.3.1_21 | |
Sun SDK | =1.3.1_22 | |
Sun SDK | =1.3.1_23 | |
Sun SDK | =1.3.1_24 | |
Sun SDK | =1.3.1_25 | |
Microsoft Windows | ||
Sun Java SE | ||
Sun JDK | =1.6.0-update2 | |
Sun JRE | =1.4.2_01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3869 has a critical severity rating due to the potential for remote code execution through a stack-based buffer overflow.
Fix CVE-2009-3869 by updating to at least JDK and JRE 5.0 Update 22, JDK and JRE 6 Update 17, or later.
CVE-2009-3869 affects Sun Java SE versions prior to Update 22 for JDK and JRE 5.0 and Update 17 for JDK and JRE 6.
CVE-2009-3869 is a stack-based buffer overflow vulnerability.
Yes, CVE-2009-3869 specifically affects the setDiffICM function in the Abstract Window Toolkit (AWT) of the Java Runtime Environment.