First published: Thu Oct 22 2009(Updated: )
Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and attack vectors, related to failure to clone arrays that are returned by the getConfigurations function, aka Bug Id 6822057.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sun JRE | =1.6.0-update_3 | |
Sun JRE | =1.5.0-update_14 | |
Sun JRE | =1.6.0-update_5 | |
Sun JRE | =1.5.0-update_13 | |
Sun JRE | =1.5.0-update_6 | |
Sun JRE | =1.5.0-update_11 | |
Sun JRE | =1.6.0-update_13 | |
Sun JRE | =1.5.0-update_12 | |
Sun JRE | =1.6.0-update_1 | |
Sun JRE | =1.6.0-update_2 | |
Sun JRE | =1.6.0-update_15 | |
Sun JRE | =1.5.0-update_15 | |
Sun JRE | =1.5.0-update_5 | |
Sun JRE | =1.6.0-update_6 | |
Sun JRE | =1.5.0-update_3 | |
Sun JRE | =1.5.0-update_19 | |
Sun JRE | =1.5.0-update_16 | |
Sun Openjdk | ||
Sun JRE | =1.6.0-update_10 | |
Sun JRE | =1.5.0-update_2 | |
Sun JRE | <=1.5.0 | |
Sun JRE | =1.5.0-update_18 | |
Sun JRE | =1.5.0-update_20 | |
Sun JRE | =1.6.0-update_8 | |
Sun JRE | =1.5.0-update_8 | |
Sun JRE | =1.5.0-update_1 | |
Sun JRE | =1.5.0-update_17 | |
Sun JRE | =1.5.0-update_4 | |
Sun JRE | =1.5.0-update10 | |
Sun JRE | =1.6.0-update_7 | |
Sun JRE | =1.6.0-update_14 | |
Sun JRE | =1.5.0-update_7 | |
Sun JRE | <=1.6.0 | |
Sun JRE | =1.6.0-update_4 | |
Sun JRE | =1.5.0-update_9 | |
Sun JRE | =1.6.0-update_9 | |
Sun JRE | =1.6.0-update_12 | |
Sun JRE | =1.6.0-update_11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-3879 is currently unknown due to the unspecified nature of the vulnerabilities.
To fix CVE-2009-3879, it is recommended to upgrade to the latest versions of Sun Java SE or OpenJDK.
CVE-2009-3879 affects multiple versions of Sun Java SE 5.0 and 6, specifically those prior to Update 22 for 5.0 and Update 17 for 6.
The attack vectors for CVE-2009-3879 are not clearly defined as the vulnerabilities are unspecified.
There are no documented workarounds for CVE-2009-3879; the best mitigation is upgrading the affected software.