CVE Vulnerabilities

CVE-2009-1190

Published: Apr 27, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.

Affected Software

NameVendorStart VersionEnd Version
JdkSun*1.5.0 (including)
JdkSun1.1.0 (including)1.1.0 (including)
JdkSun1.1.6 (including)1.1.6 (including)
JdkSun1.1.6-update7 (including)1.1.6-update7 (including)
JdkSun1.1.7b (including)1.1.7b (including)
JdkSun1.1.7b-update5 (including)1.1.7b-update5 (including)
JdkSun1.1.8-update10 (including)1.1.8-update10 (including)
JdkSun1.1.8-update13 (including)1.1.8-update13 (including)
JdkSun1.1.8-update14 (including)1.1.8-update14 (including)
JdkSun1.1.8-update2 (including)1.1.8-update2 (including)
JdkSun1.1.8-update7 (including)1.1.8-update7 (including)
JdkSun1.1.8-update8 (including)1.1.8-update8 (including)
JdkSun1.2.0 (including)1.2.0 (including)
JdkSun1.2.1 (including)1.2.1 (including)
JdkSun1.2.1-update3 (including)1.2.1-update3 (including)
JdkSun1.2.2-update4 (including)1.2.2-update4 (including)
JdkSun1.2.2-update5 (including)1.2.2-update5 (including)
JdkSun1.3.0 (including)1.3.0 (including)
JdkSun1.3.0_01 (including)1.3.0_01 (including)
JdkSun1.3.0_02 (including)1.3.0_02 (including)
JdkSun1.3.0_03 (including)1.3.0_03 (including)
JdkSun1.3.0_04 (including)1.3.0_04 (including)
JdkSun1.3.0_05 (including)1.3.0_05 (including)
JdkSun1.3.1 (including)1.3.1 (including)
JdkSun1.3.1-update19 (including)1.3.1-update19 (including)
JdkSun1.3.1-update20 (including)1.3.1-update20 (including)
JdkSun1.3.1_01 (including)1.3.1_01 (including)
JdkSun1.3.1_01a (including)1.3.1_01a (including)
JdkSun1.3.1_02 (including)1.3.1_02 (including)
JdkSun1.3.1_03 (including)1.3.1_03 (including)
JdkSun1.3.1_04 (including)1.3.1_04 (including)
JdkSun1.3.1_05 (including)1.3.1_05 (including)
JdkSun1.3.1_06 (including)1.3.1_06 (including)
JdkSun1.3.1_07 (including)1.3.1_07 (including)
JdkSun1.3.1_08 (including)1.3.1_08 (including)
JdkSun1.3.1_09 (including)1.3.1_09 (including)
JdkSun1.3.1_10 (including)1.3.1_10 (including)
JdkSun1.3.1_11 (including)1.3.1_11 (including)
JdkSun1.3.1_12 (including)1.3.1_12 (including)
JdkSun1.3.1_13 (including)1.3.1_13 (including)
JdkSun1.3.1_14 (including)1.3.1_14 (including)
JdkSun1.3.1_15 (including)1.3.1_15 (including)
JdkSun1.3.1_16 (including)1.3.1_16 (including)
JdkSun1.3.1_17 (including)1.3.1_17 (including)
JdkSun1.3.1_18 (including)1.3.1_18 (including)
JdkSun1.3.1_19 (including)1.3.1_19 (including)
JdkSun1.3.1_20 (including)1.3.1_20 (including)
JdkSun1.3.1_21 (including)1.3.1_21 (including)
JdkSun1.3.1_22 (including)1.3.1_22 (including)
JdkSun1.3.1_23 (including)1.3.1_23 (including)
JdkSun1.3.1_24 (including)1.3.1_24 (including)
JdkSun1.3.1_25 (including)1.3.1_25 (including)
JdkSun1.3.1_26 (including)1.3.1_26 (including)
JdkSun1.3.1_27 (including)1.3.1_27 (including)
JdkSun1.3.1_28 (including)1.3.1_28 (including)
JdkSun1.4.0 (including)1.4.0 (including)
JdkSun1.4.0_01 (including)1.4.0_01 (including)
JdkSun1.4.0_02 (including)1.4.0_02 (including)
JdkSun1.4.0_03 (including)1.4.0_03 (including)
JdkSun1.4.0_04 (including)1.4.0_04 (including)
JdkSun1.4.1 (including)1.4.1 (including)
JdkSun1.4.1_01 (including)1.4.1_01 (including)
JdkSun1.4.1_02 (including)1.4.1_02 (including)
JdkSun1.4.1_03 (including)1.4.1_03 (including)
JdkSun1.4.1_04 (including)1.4.1_04 (including)
JdkSun1.4.1_05 (including)1.4.1_05 (including)
JdkSun1.4.1_06 (including)1.4.1_06 (including)
JdkSun1.4.1_07 (including)1.4.1_07 (including)
JdkSun1.4.2 (including)1.4.2 (including)
JdkSun1.4.2_1 (including)1.4.2_1 (including)
JdkSun1.4.2_2 (including)1.4.2_2 (including)
JdkSun1.4.2_3 (including)1.4.2_3 (including)
JdkSun1.4.2_4 (including)1.4.2_4 (including)
JdkSun1.4.2_5 (including)1.4.2_5 (including)
JdkSun1.4.2_6 (including)1.4.2_6 (including)
JdkSun1.4.2_7 (including)1.4.2_7 (including)
JdkSun1.4.2_8 (including)1.4.2_8 (including)
JdkSun1.4.2_9 (including)1.4.2_9 (including)
JdkSun1.4.2_10 (including)1.4.2_10 (including)
JdkSun1.4.2_11 (including)1.4.2_11 (including)
JdkSun1.4.2_12 (including)1.4.2_12 (including)
JdkSun1.4.2_13 (including)1.4.2_13 (including)
JdkSun1.4.2_14 (including)1.4.2_14 (including)
JdkSun1.4.2_15 (including)1.4.2_15 (including)
JdkSun1.4.2_16 (including)1.4.2_16 (including)
JdkSun1.4.2_17 (including)1.4.2_17 (including)
JdkSun1.4.2_18 (including)1.4.2_18 (including)
JdkSun1.4.2_19 (including)1.4.2_19 (including)
JdkSun1.5.0 (including)1.5.0 (including)
JdkSun1.5.0-update_1 (including)1.5.0-update_1 (including)
JdkSun1.5.0-update_10 (including)1.5.0-update_10 (including)
JdkSun1.5.0-update_11 (including)1.5.0-update_11 (including)
JdkSun1.5.0-update_12 (including)1.5.0-update_12 (including)
JdkSun1.5.0-update_13 (including)1.5.0-update_13 (including)
JdkSun1.5.0-update_14 (including)1.5.0-update_14 (including)
JdkSun1.5.0-update_15 (including)1.5.0-update_15 (including)
JdkSun1.5.0-update_16 (including)1.5.0-update_16 (including)
JdkSun1.5.0-update_17 (including)1.5.0-update_17 (including)
JdkSun1.5.0-update_18 (including)1.5.0-update_18 (including)
JdkSun1.5.0-update_19 (including)1.5.0-update_19 (including)
JdkSun1.5.0-update_2 (including)1.5.0-update_2 (including)
JdkSun1.5.0-update_20 (including)1.5.0-update_20 (including)
JdkSun1.5.0-update_21 (including)1.5.0-update_21 (including)
JdkSun1.5.0-update_3 (including)1.5.0-update_3 (including)
JdkSun1.5.0-update_4 (including)1.5.0-update_4 (including)
JdkSun1.5.0-update_5 (including)1.5.0-update_5 (including)
JdkSun1.5.0-update_6 (including)1.5.0-update_6 (including)
JdkSun1.5.0-update_7 (including)1.5.0-update_7 (including)
JdkSun1.5.0-update_8 (including)1.5.0-update_8 (including)
JdkSun1.5.0-update_9 (including)1.5.0-update_9 (including)
JdkSun1.5.0-update1 (including)1.5.0-update1 (including)
JdkSun1.5.0-update10 (including)1.5.0-update10 (including)
JdkSun1.5.0-update11 (including)1.5.0-update11 (including)
JdkSun1.5.0-update11_b03 (including)1.5.0-update11_b03 (including)
JdkSun1.5.0-update12 (including)1.5.0-update12 (including)
JdkSun1.5.0-update13 (including)1.5.0-update13 (including)
JdkSun1.5.0-update14 (including)1.5.0-update14 (including)
JdkSun1.5.0-update15 (including)1.5.0-update15 (including)
JdkSun1.5.0-update16 (including)1.5.0-update16 (including)
JdkSun1.5.0-update17 (including)1.5.0-update17 (including)
JdkSun1.5.0-update18 (including)1.5.0-update18 (including)
JdkSun1.5.0-update19 (including)1.5.0-update19 (including)
JdkSun1.5.0-update2 (including)1.5.0-update2 (including)
JdkSun1.5.0-update20 (including)1.5.0-update20 (including)
JdkSun1.5.0-update21 (including)1.5.0-update21 (including)
JdkSun1.5.0-update22 (including)1.5.0-update22 (including)
JdkSun1.5.0-update23 (including)1.5.0-update23 (including)
JdkSun1.5.0-update24 (including)1.5.0-update24 (including)
JdkSun1.5.0-update25 (including)1.5.0-update25 (including)
JdkSun1.5.0-update3 (including)1.5.0-update3 (including)
JdkSun1.5.0-update4 (including)1.5.0-update4 (including)
JdkSun1.5.0-update5 (including)1.5.0-update5 (including)
JdkSun1.5.0-update6 (including)1.5.0-update6 (including)
JdkSun1.5.0-update7 (including)1.5.0-update7 (including)
JdkSun1.5.0-update7_b03 (including)1.5.0-update7_b03 (including)
JdkSun1.5.0-update8 (including)1.5.0-update8 (including)
JdkSun1.5.0-update9 (including)1.5.0-update9 (including)
JdkSun1.5.0_03 (including)1.5.0_03 (including)
Sun-java5Ubuntudapper*
Sun-java5Ubuntuhardy*
Sun-java5Ubuntuintrepid*
Sun-java5Ubuntujaunty*

References