First published: Thu Nov 05 2009(Updated: )
Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK | =1.5.0-update_9 | |
OpenJDK | =1.6.0-update_4 | |
Sun JRE | =1.6.0-update_3 | |
Sun JRE | =1.5.0-update_14 | |
Sun JRE | =1.6.0-update_5 | |
OpenJDK | =1.6.0-update_7 | |
OpenJDK | =1.5.0-update_15 | |
OpenJDK | =1.5.0-update_19 | |
Sun JRE | =1.5.0-update_13 | |
OpenJDK | =1.6.0-update_13 | |
Sun JRE | =1.5.0-update_21 | |
Sun JRE | =1.5.0-update_6 | |
Sun JRE | =1.5.0-update_11 | |
Sun JRE | =1.6.0-update_13 | |
Sun JRE | =1.5.0-update_12 | |
OpenJDK | =1.6.0-update_9 | |
OpenJDK | =1.5.0-update_18 | |
Sun JRE | =1.6.0-update_1 | |
Sun JRE | =1.6.0-update_2 | |
OpenJDK | =1.6.0-update_3 | |
Sun JRE | =1.6.0-update_16 | |
OpenJDK | =1.6.0-update_11 | |
OpenJDK | =1.6.0-update_10 | |
Sun JRE | =1.6.0-update_15 | |
OpenJDK | =1.5.0-update_10 | |
Sun JRE | =1.5.0-update_15 | |
Sun JRE | =1.5.0-update_5 | |
OpenJDK | =1.5.0-update_5 | |
Sun JRE | =1.6.0-update_6 | |
OpenJDK | =1.6.0-update_14 | |
OpenJDK | =1.5.0-update_1 | |
Sun JRE | =1.5.0-update_3 | |
Sun JRE | =1.5.0-update_19 | |
OpenJDK | =1.5.0-update_17 | |
Sun JRE | =1.5.0-update_16 | |
OpenJDK | =1.5.0-update_6 | |
OpenJDK | =1.6.0-update_5 | |
OpenJDK | =1.5.0-update_20 | |
OpenJDK | =1.6.0-update_8 | |
OpenJDK | =1.5.0-update_13 | |
Sun JRE | =1.6.0-update_10 | |
Sun JRE | =1.5.0-update_2 | |
Sun JRE | =1.5.0-update_18 | |
Sun JRE | =1.5.0-update_20 | |
OpenJDK | =1.6.0-update_16 | |
Sun JRE | =1.6.0-update_8 | |
OpenJDK | =1.5.0-update_16 | |
OpenJDK | =1.5.0-update_4 | |
Sun JRE | =1.5.0-update_8 | |
OpenJDK | =1.5.0-update_3 | |
Sun JRE | =1.5.0-update_1 | |
Sun JRE | =1.5.0-update_17 | |
OpenJDK | =1.5.0-update_12 | |
Sun JRE | =1.5.0-update_4 | |
OpenJDK | =1.5.0-update_7 | |
OpenJDK | =1.5.0-update_21 | |
Sun JRE | =1.6.0-update_7 | |
Sun JRE | =1.6.0-update_14 | |
OpenJDK | =1.5.0-update_11 | |
OpenJDK | =1.6.0-update_15 | |
OpenJDK | =1.6.0-update_12 | |
Sun JRE | =1.5.0-update_7 | |
Sun JRE | =1.6.0-update_4 | |
Sun JRE | =1.5.0-update_9 | |
OpenJDK | =1.6.0-update_1 | |
OpenJDK | =1.6.0-update_6 | |
Sun JRE | =1.6.0-update_9 | |
Sun JRE | =1.6.0-update_12 | |
OpenJDK | =1.5.0-update_14 | |
OpenJDK | =1.5.0-update_8 | |
OpenJDK | =1.5.0-update_2 | |
Sun JRE | =1.6.0-update_11 | |
Sun JRE | =1.4.2_1 | |
Sun JRE | =1.4.2_2 | |
Sun JRE | =1.4.2_02 | |
Sun JRE | =1.4.2_03 | |
Sun JRE | =1.4.2_3 | |
Sun JRE | =1.4.2_4 | |
Sun JRE | =1.4.2_04 | |
Sun JRE | =1.4.2_05 | |
Sun JRE | =1.4.2_5 | |
Sun JRE | =1.4.2_06 | |
Sun JRE | =1.4.2_6 | |
Sun JRE | =1.4.2_7 | |
Sun JRE | =1.4.2_07 | |
Sun JRE | =1.4.2_8 | |
Sun JRE | =1.4.2_08 | |
Sun JRE | =1.4.2_09 | |
Sun JRE | =1.4.2_9 | |
Sun JRE | =1.4.2_10 | |
Sun JRE | =1.4.2_11 | |
Sun JRE | =1.4.2_12 | |
Sun JRE | =1.4.2_13 | |
Sun JRE | =1.4.2_14 | |
Sun JRE | =1.4.2_15 | |
Sun JRE | =1.4.2_16 | |
Sun JRE | =1.4.2_17 | |
Sun JRE | =1.4.2_18 | |
Sun JRE | =1.4.2_19 | |
Sun JRE | =1.4.2_20 | |
Sun JRE | =1.4.2_21 | |
Sun JRE | =1.4.2_22 | |
Sun SDK | =1.4.2_01 | |
Sun SDK | =1.4.2_1 | |
Sun SDK | =1.4.2_2 | |
Sun SDK | =1.4.2_02 | |
Sun SDK | =1.4.2_03 | |
Sun SDK | =1.4.2_3 | |
Sun SDK | =1.4.2_04 | |
Sun SDK | =1.4.2_4 | |
Sun SDK | =1.4.2_5 | |
Sun SDK | =1.4.2_05 | |
Sun SDK | =1.4.2_6 | |
Sun SDK | =1.4.2_06 | |
Sun SDK | =1.4.2_07 | |
Sun SDK | =1.4.2_7 | |
Sun SDK | =1.4.2_8 | |
Sun SDK | =1.4.2_08 | |
Sun SDK | =1.4.2_09 | |
Sun SDK | =1.4.2_9 | |
Sun SDK | =1.4.2_10 | |
Sun SDK | =1.4.2_11 | |
Sun SDK | =1.4.2_12 | |
Sun SDK | =1.4.2_13 | |
Sun SDK | =1.4.2_14 | |
Sun SDK | =1.4.2_15 | |
Sun SDK | =1.4.2_16 | |
Sun SDK | =1.4.2_17 | |
Sun SDK | =1.4.2_18 | |
Sun SDK | =1.4.2_19 | |
Sun SDK | =1.4.2_20 | |
Sun SDK | =1.4.2_21 | |
Sun SDK | =1.4.2_22 | |
Oracle Solaris SPARC | ||
Sun JRE | =1.3.1_1 | |
Sun JRE | =1.3.1_01 | |
Sun JRE | =1.3.1_01a | |
Sun JRE | =1.3.1_02 | |
Sun JRE | =1.3.1_2 | |
Sun JRE | =1.3.1_03 | |
Sun JRE | =1.3.1_3 | |
Sun JRE | =1.3.1_4 | |
Sun JRE | =1.3.1_04 | |
Sun JRE | =1.3.1_05 | |
Sun JRE | =1.3.1_5 | |
Sun JRE | =1.3.1_06 | |
Sun JRE | =1.3.1_6 | |
Sun JRE | =1.3.1_07 | |
Sun JRE | =1.3.1_7 | |
Sun JRE | =1.3.1_8 | |
Sun JRE | =1.3.1_08 | |
Sun JRE | =1.3.1_9 | |
Sun JRE | =1.3.1_09 | |
Sun JRE | =1.3.1_10 | |
Sun JRE | =1.3.1_11 | |
Sun JRE | =1.3.1_12 | |
Sun JRE | =1.3.1_13 | |
Sun JRE | =1.3.1_14 | |
Sun JRE | =1.3.1_15 | |
Sun JRE | =1.3.1_16 | |
Sun JRE | =1.3.1_17 | |
Sun JRE | =1.3.1_18 | |
Sun JRE | =1.3.1_19 | |
Sun JRE | =1.3.1_20 | |
Sun JRE | =1.3.1_21 | |
Sun JRE | =1.3.1_22 | |
Sun JRE | =1.3.1_23 | |
Sun JRE | =1.3.1_24 | |
Sun JRE | =1.3.1_25 | |
Sun SDK | =1.3.1_01 | |
Sun SDK | =1.3.1_01a | |
Sun SDK | =1.3.1_2 | |
Sun SDK | =1.3.1_02 | |
Sun SDK | =1.3.1_03 | |
Sun SDK | =1.3.1_3 | |
Sun SDK | =1.3.1_4 | |
Sun SDK | =1.3.1_04 | |
Sun SDK | =1.3.1_5 | |
Sun SDK | =1.3.1_05 | |
Sun SDK | =1.3.1_6 | |
Sun SDK | =1.3.1_06 | |
Sun SDK | =1.3.1_7 | |
Sun SDK | =1.3.1_07 | |
Sun SDK | =1.3.1_8 | |
Sun SDK | =1.3.1_08 | |
Sun SDK | =1.3.1_9 | |
Sun SDK | =1.3.1_09 | |
Sun SDK | =1.3.1_10 | |
Sun SDK | =1.3.1_11 | |
Sun SDK | =1.3.1_12 | |
Sun SDK | =1.3.1_13 | |
Sun SDK | =1.3.1_14 | |
Sun SDK | =1.3.1_15 | |
Sun SDK | =1.3.1_16 | |
Sun SDK | =1.3.1_17 | |
Sun SDK | =1.3.1_18 | |
Sun SDK | =1.3.1_19 | |
Sun SDK | =1.3.1_20 | |
Sun SDK | =1.3.1_21 | |
Sun SDK | =1.3.1_22 | |
Sun SDK | =1.3.1_23 | |
Sun SDK | =1.3.1_24 | |
Sun SDK | =1.3.1_25 | |
Microsoft Windows | ||
Sun Java SE | ||
OpenJDK | =1.6.0-update2 | |
Sun JRE | =1.4.2_01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3871 has a severity rating of high due to its potential for remote code execution.
To fix CVE-2009-3871, update your Java Runtime Environment to the latest version or apply the necessary patches provided by Oracle.
CVE-2009-3871 affects Java SE version 5.0 before Update 22, and Java SE version 6 before Update 17.
CVE-2009-3871 primarily affects systems running vulnerable versions of Java, including various platforms like Windows and Solaris.
As a workaround for CVE-2009-3871, users can disable Java functionality or restrict the execution of Java applets in their browsers until the patch is applied.