CVE Vulnerabilities

CVE-2009-3880

Published: Nov 09, 2009 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW

The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitive information via vectors related to the implementation of Component, KeyboardFocusManager, and DefaultKeyboardFocusManager, aka Bug Id 6664512.

Affected Software

Name Vendor Start Version End Version
Jre Sun * 1.5.0 (including)
Jre Sun * 1.6.0 (including)
Jre Sun 1.5.0-update_1 (including) 1.5.0-update_1 (including)
Jre Sun 1.5.0-update_11 (including) 1.5.0-update_11 (including)
Jre Sun 1.5.0-update_12 (including) 1.5.0-update_12 (including)
Jre Sun 1.5.0-update_13 (including) 1.5.0-update_13 (including)
Jre Sun 1.5.0-update_14 (including) 1.5.0-update_14 (including)
Jre Sun 1.5.0-update_15 (including) 1.5.0-update_15 (including)
Jre Sun 1.5.0-update_16 (including) 1.5.0-update_16 (including)
Jre Sun 1.5.0-update_17 (including) 1.5.0-update_17 (including)
Jre Sun 1.5.0-update_18 (including) 1.5.0-update_18 (including)
Jre Sun 1.5.0-update_19 (including) 1.5.0-update_19 (including)
Jre Sun 1.5.0-update_2 (including) 1.5.0-update_2 (including)
Jre Sun 1.5.0-update_20 (including) 1.5.0-update_20 (including)
Jre Sun 1.5.0-update_3 (including) 1.5.0-update_3 (including)
Jre Sun 1.5.0-update_4 (including) 1.5.0-update_4 (including)
Jre Sun 1.5.0-update_5 (including) 1.5.0-update_5 (including)
Jre Sun 1.5.0-update_6 (including) 1.5.0-update_6 (including)
Jre Sun 1.5.0-update_7 (including) 1.5.0-update_7 (including)
Jre Sun 1.5.0-update_8 (including) 1.5.0-update_8 (including)
Jre Sun 1.5.0-update_9 (including) 1.5.0-update_9 (including)
Jre Sun 1.5.0-update10 (including) 1.5.0-update10 (including)
Jre Sun 1.6.0-update_1 (including) 1.6.0-update_1 (including)
Jre Sun 1.6.0-update_10 (including) 1.6.0-update_10 (including)
Jre Sun 1.6.0-update_11 (including) 1.6.0-update_11 (including)
Jre Sun 1.6.0-update_12 (including) 1.6.0-update_12 (including)
Jre Sun 1.6.0-update_13 (including) 1.6.0-update_13 (including)
Jre Sun 1.6.0-update_14 (including) 1.6.0-update_14 (including)
Jre Sun 1.6.0-update_15 (including) 1.6.0-update_15 (including)
Jre Sun 1.6.0-update_2 (including) 1.6.0-update_2 (including)
Jre Sun 1.6.0-update_3 (including) 1.6.0-update_3 (including)
Jre Sun 1.6.0-update_4 (including) 1.6.0-update_4 (including)
Jre Sun 1.6.0-update_5 (including) 1.6.0-update_5 (including)
Jre Sun 1.6.0-update_6 (including) 1.6.0-update_6 (including)
Jre Sun 1.6.0-update_7 (including) 1.6.0-update_7 (including)
Jre Sun 1.6.0-update_8 (including) 1.6.0-update_8 (including)
Jre Sun 1.6.0-update_9 (including) 1.6.0-update_9 (including)
Openjdk Sun * *
Extras for RHEL 4 RedHat java-1.6.0-sun-1:1.6.0.17-1jpp.1.el4 *
Extras for RHEL 4 RedHat java-1.5.0-sun-0:1.5.0.22-1jpp.1.el4 *
Red Hat Enterprise Linux 5 RedHat java-1.6.0-openjdk-1:1.6.0.0-1.7.b09.el5 *
Red Hat Network Satellite Server v 5.1 RedHat java-1.5.0-sun-0:1.5.0.22-1jpp.1.el4 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.6.0-sun-1:1.6.0.17-1jpp.2.el5 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.5.0-sun-0:1.5.0.22-1jpp.1.el5 *
Openjdk-6 Ubuntu hardy *
Openjdk-6 Ubuntu intrepid *
Openjdk-6 Ubuntu jaunty *
Openjdk-6 Ubuntu karmic *
Openjdk-6 Ubuntu upstream *
Sun-java5 Ubuntu dapper *
Sun-java5 Ubuntu intrepid *
Sun-java5 Ubuntu jaunty *
Sun-java5 Ubuntu upstream *
Sun-java6 Ubuntu hardy *
Sun-java6 Ubuntu intrepid *
Sun-java6 Ubuntu jaunty *
Sun-java6 Ubuntu karmic *
Sun-java6 Ubuntu lucid *
Sun-java6 Ubuntu upstream *

References