CVE Vulnerabilities

CVE-2009-3875

Published: Nov 05, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to timing attack vulnerabilities, aka Bug Id 6863503.

Affected Software

NameVendorStart VersionEnd Version
JdkSun1.5.0-update1 (including)1.5.0-update1 (including)
JdkSun1.5.0-update10 (including)1.5.0-update10 (including)
JdkSun1.5.0-update11 (including)1.5.0-update11 (including)
JdkSun1.5.0-update11_b03 (including)1.5.0-update11_b03 (including)
JdkSun1.5.0-update12 (including)1.5.0-update12 (including)
JdkSun1.5.0-update13 (including)1.5.0-update13 (including)
JdkSun1.5.0-update14 (including)1.5.0-update14 (including)
JdkSun1.5.0-update15 (including)1.5.0-update15 (including)
JdkSun1.5.0-update16 (including)1.5.0-update16 (including)
JdkSun1.5.0-update17 (including)1.5.0-update17 (including)
JdkSun1.5.0-update18 (including)1.5.0-update18 (including)
JdkSun1.5.0-update19 (including)1.5.0-update19 (including)
JdkSun1.5.0-update2 (including)1.5.0-update2 (including)
JdkSun1.5.0-update20 (including)1.5.0-update20 (including)
JdkSun1.5.0-update21 (including)1.5.0-update21 (including)
JdkSun1.5.0-update3 (including)1.5.0-update3 (including)
JdkSun1.5.0-update4 (including)1.5.0-update4 (including)
JdkSun1.5.0-update5 (including)1.5.0-update5 (including)
JdkSun1.5.0-update6 (including)1.5.0-update6 (including)
JdkSun1.5.0-update7 (including)1.5.0-update7 (including)
JdkSun1.5.0-update7_b03 (including)1.5.0-update7_b03 (including)
JdkSun1.5.0-update8 (including)1.5.0-update8 (including)
JdkSun1.5.0-update9 (including)1.5.0-update9 (including)
JdkSun1.6.0-update1 (including)1.6.0-update1 (including)
JdkSun1.6.0-update10 (including)1.6.0-update10 (including)
JdkSun1.6.0-update11 (including)1.6.0-update11 (including)
JdkSun1.6.0-update12 (including)1.6.0-update12 (including)
JdkSun1.6.0-update13 (including)1.6.0-update13 (including)
JdkSun1.6.0-update14 (including)1.6.0-update14 (including)
JdkSun1.6.0-update15 (including)1.6.0-update15 (including)
JdkSun1.6.0-update16 (including)1.6.0-update16 (including)
JdkSun1.6.0-update2 (including)1.6.0-update2 (including)
JdkSun1.6.0-update3 (including)1.6.0-update3 (including)
JdkSun1.6.0-update4 (including)1.6.0-update4 (including)
JdkSun1.6.0-update5 (including)1.6.0-update5 (including)
JdkSun1.6.0-update6 (including)1.6.0-update6 (including)
JdkSun1.6.0-update7 (including)1.6.0-update7 (including)
JdkSun1.6.0-update8 (including)1.6.0-update8 (including)
JdkSun1.6.0-update9 (including)1.6.0-update9 (including)
JreSun1.4.2_1 (including)1.4.2_1 (including)
JreSun1.4.2_2 (including)1.4.2_2 (including)
JreSun1.4.2_02 (including)1.4.2_02 (including)
JreSun1.4.2_03 (including)1.4.2_03 (including)
JreSun1.4.2_3 (including)1.4.2_3 (including)
JreSun1.4.2_4 (including)1.4.2_4 (including)
JreSun1.4.2_04 (including)1.4.2_04 (including)
JreSun1.4.2_05 (including)1.4.2_05 (including)
JreSun1.4.2_5 (including)1.4.2_5 (including)
JreSun1.4.2_06 (including)1.4.2_06 (including)
JreSun1.4.2_6 (including)1.4.2_6 (including)
JreSun1.4.2_7 (including)1.4.2_7 (including)
JreSun1.4.2_07 (including)1.4.2_07 (including)
JreSun1.4.2_8 (including)1.4.2_8 (including)
JreSun1.4.2_08 (including)1.4.2_08 (including)
JreSun1.4.2_09 (including)1.4.2_09 (including)
JreSun1.4.2_9 (including)1.4.2_9 (including)
JreSun1.4.2_10 (including)1.4.2_10 (including)
JreSun1.4.2_11 (including)1.4.2_11 (including)
JreSun1.4.2_12 (including)1.4.2_12 (including)
JreSun1.4.2_13 (including)1.4.2_13 (including)
JreSun1.4.2_14 (including)1.4.2_14 (including)
JreSun1.4.2_15 (including)1.4.2_15 (including)
JreSun1.4.2_16 (including)1.4.2_16 (including)
JreSun1.4.2_17 (including)1.4.2_17 (including)
JreSun1.4.2_18 (including)1.4.2_18 (including)
JreSun1.4.2_19 (including)1.4.2_19 (including)
JreSun1.4.2_20 (including)1.4.2_20 (including)
JreSun1.4.2_21 (including)1.4.2_21 (including)
JreSun1.4.2_22 (including)1.4.2_22 (including)
JreSun1.4.2_23 (including)1.4.2_23 (including)
JreSun1.5.0-update1 (including)1.5.0-update1 (including)
JreSun1.5.0-update10 (including)1.5.0-update10 (including)
JreSun1.5.0-update11 (including)1.5.0-update11 (including)
JreSun1.5.0-update12 (including)1.5.0-update12 (including)
JreSun1.5.0-update13 (including)1.5.0-update13 (including)
JreSun1.5.0-update14 (including)1.5.0-update14 (including)
JreSun1.5.0-update15 (including)1.5.0-update15 (including)
JreSun1.5.0-update16 (including)1.5.0-update16 (including)
JreSun1.5.0-update17 (including)1.5.0-update17 (including)
JreSun1.5.0-update18 (including)1.5.0-update18 (including)
JreSun1.5.0-update19 (including)1.5.0-update19 (including)
JreSun1.5.0-update2 (including)1.5.0-update2 (including)
JreSun1.5.0-update20 (including)1.5.0-update20 (including)
JreSun1.5.0-update21 (including)1.5.0-update21 (including)
JreSun1.5.0-update3 (including)1.5.0-update3 (including)
JreSun1.5.0-update4 (including)1.5.0-update4 (including)
JreSun1.5.0-update5 (including)1.5.0-update5 (including)
JreSun1.5.0-update6 (including)1.5.0-update6 (including)
JreSun1.5.0-update7 (including)1.5.0-update7 (including)
JreSun1.5.0-update8 (including)1.5.0-update8 (including)
JreSun1.5.0-update9 (including)1.5.0-update9 (including)
JreSun1.6.0-update_1 (including)1.6.0-update_1 (including)
JreSun1.6.0-update_2 (including)1.6.0-update_2 (including)
JreSun1.6.0-update_3 (including)1.6.0-update_3 (including)
JreSun1.6.0-update10 (including)1.6.0-update10 (including)
JreSun1.6.0-update11 (including)1.6.0-update11 (including)
JreSun1.6.0-update12 (including)1.6.0-update12 (including)
JreSun1.6.0-update13 (including)1.6.0-update13 (including)
JreSun1.6.0-update14 (including)1.6.0-update14 (including)
JreSun1.6.0-update15 (including)1.6.0-update15 (including)
JreSun1.6.0-update16 (including)1.6.0-update16 (including)
JreSun1.6.0-update4 (including)1.6.0-update4 (including)
JreSun1.6.0-update5 (including)1.6.0-update5 (including)
JreSun1.6.0-update6 (including)1.6.0-update6 (including)
JreSun1.6.0-update7 (including)1.6.0-update7 (including)
JreSun1.6.0-update8 (including)1.6.0-update8 (including)
JreSun1.6.0-update9 (including)1.6.0-update9 (including)
SdkSun1.4.2_01 (including)1.4.2_01 (including)
SdkSun1.4.2_1 (including)1.4.2_1 (including)
SdkSun1.4.2_2 (including)1.4.2_2 (including)
SdkSun1.4.2_02 (including)1.4.2_02 (including)
SdkSun1.4.2_03 (including)1.4.2_03 (including)
SdkSun1.4.2_3 (including)1.4.2_3 (including)
SdkSun1.4.2_04 (including)1.4.2_04 (including)
SdkSun1.4.2_4 (including)1.4.2_4 (including)
SdkSun1.4.2_5 (including)1.4.2_5 (including)
SdkSun1.4.2_05 (including)1.4.2_05 (including)
SdkSun1.4.2_6 (including)1.4.2_6 (including)
SdkSun1.4.2_06 (including)1.4.2_06 (including)
SdkSun1.4.2_07 (including)1.4.2_07 (including)
SdkSun1.4.2_7 (including)1.4.2_7 (including)
SdkSun1.4.2_8 (including)1.4.2_8 (including)
SdkSun1.4.2_08 (including)1.4.2_08 (including)
SdkSun1.4.2_09 (including)1.4.2_09 (including)
SdkSun1.4.2_9 (including)1.4.2_9 (including)
SdkSun1.4.2_10 (including)1.4.2_10 (including)
SdkSun1.4.2_11 (including)1.4.2_11 (including)
SdkSun1.4.2_12 (including)1.4.2_12 (including)
SdkSun1.4.2_13 (including)1.4.2_13 (including)
SdkSun1.4.2_14 (including)1.4.2_14 (including)
SdkSun1.4.2_15 (including)1.4.2_15 (including)
SdkSun1.4.2_16 (including)1.4.2_16 (including)
SdkSun1.4.2_17 (including)1.4.2_17 (including)
SdkSun1.4.2_18 (including)1.4.2_18 (including)
SdkSun1.4.2_19 (including)1.4.2_19 (including)
SdkSun1.4.2_20 (including)1.4.2_20 (including)
SdkSun1.4.2_21 (including)1.4.2_21 (including)
SdkSun1.4.2_22 (including)1.4.2_22 (including)
SdkSun1.4.2_23 (including)1.4.2_23 (including)
Extras for RHEL 3RedHatjava-1.4.2-ibm-0:1.4.2.13.3-1jpp.1.el3*
Extras for RHEL 4RedHatjava-1.6.0-sun-1:1.6.0.17-1jpp.1.el4*
Extras for RHEL 4RedHatjava-1.5.0-sun-0:1.5.0.22-1jpp.1.el4*
Extras for RHEL 4RedHatjava-1.4.2-ibm-0:1.4.2.13.3-1jpp.1.el4*
Extras for RHEL 4RedHatjava-1.5.0-ibm-1:1.5.0.11-1jpp.1.el4*
Extras for RHEL 4RedHatjava-1.6.0-ibm-1:1.6.0.7-1jpp.3.el4*
Red Hat Enterprise Linux 5RedHatjava-1.6.0-openjdk-1:1.6.0.0-1.7.b09.el5*
Red Hat Network Satellite Server v 5.3RedHatjava-1.6.0-ibm-1:1.6.0.7-1jpp.3.el4*
RHEL 4 for SAPRedHatjava-1.4.2-ibm-0:1.4.2.13.4.sap-1jpp.1.el4_8*
RHEL 5 for SAPRedHatjava-1.4.2-ibm-0:1.4.2.13.4.sap-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-sun-1:1.6.0.17-1jpp.2.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-sun-0:1.5.0.22-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.4.2-ibm-0:1.4.2.13.3-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-ibm-1:1.5.0.11-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-ibm-1:1.6.0.7-1jpp.2.el5*
Openjdk-6Ubuntuhardy*
Openjdk-6Ubuntuintrepid*
Openjdk-6Ubuntujaunty*
Openjdk-6Ubuntukarmic*
Openjdk-6Ubuntuupstream*
Sun-java5Ubuntudapper*
Sun-java5Ubuntuintrepid*
Sun-java5Ubuntujaunty*
Sun-java5Ubuntuupstream*
Sun-java6Ubuntuhardy*
Sun-java6Ubuntuintrepid*
Sun-java6Ubuntujaunty*
Sun-java6Ubuntukarmic*
Sun-java6Ubuntulucid*
Sun-java6Ubuntuupstream*

References