CVE Vulnerabilities

CVE-2009-2675

Published: Aug 05, 2009 | Modified: Oct 10, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.

Affected Software

Name Vendor Start Version End Version
Jdk Sun 5.0 5.0
Jdk Sun 5.0 5.0
Jre Sun 5.0 5.0
Jdk Sun 5.0 5.0
Jre Sun 5.0 5.0
Jre Sun 5.0 5.0
Jdk Sun 5.0 5.0
Jre Sun 6 6
Jre Sun * 6
Jdk Sun 6 6
Jdk Sun 6 6
Jdk Sun 5.0 5.0
Jre Sun 5.0 5.0
Jre Sun 6 6
Jdk Sun 6 6
Jre Sun 6 6
Jre Sun 5.0 5.0
Jdk Sun 5.0 5.0
Jdk Sun 5.0 5.0
Jdk Sun 6 6
Jdk Sun 6 6
Jdk Sun 6 6
Jdk Sun 5.0 5.0
Jre Sun 6 6
Jre Sun 5.0 5.0
Jre Sun 6 6
Jdk Sun 6 6
Jdk Sun 6 6
Jdk Sun * 6
Jre Sun 5.0 5.0
Jre Sun 5.0 5.0
Jre Sun 5.0 5.0
Jdk Sun 5.0 5.0
Jre Sun 5.0 5.0
Jre Sun 6 6
Jre Sun 6 6
Jre Sun 5.0 5.0
Jdk Sun 5.0 5.0
Jdk Sun 6 6
Jre Sun 6 6
Jre Sun 5.0 5.0
Jdk Sun 6 6
Jre Sun 6 6
Jre Sun 6 6
Jdk Sun 5.0 5.0
Jre Sun 5.0 5.0
Jdk Sun 5.0 5.0
Jre Sun 5.0 5.0
Jre Sun 5.0 5.0
Jre Sun 6 6
Jdk Sun 6 6
Jre Sun 5.0 5.0
Jdk Sun 5.0 5.0
Jdk Sun 5.0 5.0
Jdk Sun 5.0 5.0
Jdk Sun 5.0 5.0
Jre Sun 6 6
Jre Sun 5.0 5.0
Jre Sun 5.0 5.0
Jdk Sun 5.0 5.0
Jdk Sun 6 6

References