CVE Vulnerabilities

CVE-2009-3884

Published: Nov 09, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.

Affected Software

NameVendorStart VersionEnd Version
JreSun*1.5.0 (including)
JreSun*1.6.0 (including)
JreSun1.5.0-update_1 (including)1.5.0-update_1 (including)
JreSun1.5.0-update_11 (including)1.5.0-update_11 (including)
JreSun1.5.0-update_12 (including)1.5.0-update_12 (including)
JreSun1.5.0-update_13 (including)1.5.0-update_13 (including)
JreSun1.5.0-update_14 (including)1.5.0-update_14 (including)
JreSun1.5.0-update_15 (including)1.5.0-update_15 (including)
JreSun1.5.0-update_16 (including)1.5.0-update_16 (including)
JreSun1.5.0-update_17 (including)1.5.0-update_17 (including)
JreSun1.5.0-update_18 (including)1.5.0-update_18 (including)
JreSun1.5.0-update_19 (including)1.5.0-update_19 (including)
JreSun1.5.0-update_2 (including)1.5.0-update_2 (including)
JreSun1.5.0-update_20 (including)1.5.0-update_20 (including)
JreSun1.5.0-update_3 (including)1.5.0-update_3 (including)
JreSun1.5.0-update_4 (including)1.5.0-update_4 (including)
JreSun1.5.0-update_5 (including)1.5.0-update_5 (including)
JreSun1.5.0-update_6 (including)1.5.0-update_6 (including)
JreSun1.5.0-update_7 (including)1.5.0-update_7 (including)
JreSun1.5.0-update_8 (including)1.5.0-update_8 (including)
JreSun1.5.0-update_9 (including)1.5.0-update_9 (including)
JreSun1.5.0-update10 (including)1.5.0-update10 (including)
JreSun1.6.0-update_1 (including)1.6.0-update_1 (including)
JreSun1.6.0-update_10 (including)1.6.0-update_10 (including)
JreSun1.6.0-update_11 (including)1.6.0-update_11 (including)
JreSun1.6.0-update_12 (including)1.6.0-update_12 (including)
JreSun1.6.0-update_13 (including)1.6.0-update_13 (including)
JreSun1.6.0-update_14 (including)1.6.0-update_14 (including)
JreSun1.6.0-update_15 (including)1.6.0-update_15 (including)
JreSun1.6.0-update_2 (including)1.6.0-update_2 (including)
JreSun1.6.0-update_3 (including)1.6.0-update_3 (including)
JreSun1.6.0-update_4 (including)1.6.0-update_4 (including)
JreSun1.6.0-update_5 (including)1.6.0-update_5 (including)
JreSun1.6.0-update_6 (including)1.6.0-update_6 (including)
JreSun1.6.0-update_7 (including)1.6.0-update_7 (including)
JreSun1.6.0-update_8 (including)1.6.0-update_8 (including)
JreSun1.6.0-update_9 (including)1.6.0-update_9 (including)
OpenjdkSun**
Extras for RHEL 4RedHatjava-1.6.0-sun-1:1.6.0.17-1jpp.1.el4*
Extras for RHEL 4RedHatjava-1.5.0-sun-0:1.5.0.22-1jpp.1.el4*
Red Hat Enterprise Linux 5RedHatjava-1.6.0-openjdk-1:1.6.0.0-1.7.b09.el5*
Red Hat Network Satellite Server v 5.1RedHatjava-1.5.0-sun-0:1.5.0.22-1jpp.1.el4*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-sun-1:1.6.0.17-1jpp.2.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-sun-0:1.5.0.22-1jpp.1.el5*
Openjdk-6Ubuntuhardy*
Openjdk-6Ubuntuintrepid*
Openjdk-6Ubuntujaunty*
Openjdk-6Ubuntukarmic*
Openjdk-6Ubuntuupstream*
Sun-java5Ubuntudapper*
Sun-java5Ubuntuintrepid*
Sun-java5Ubuntujaunty*
Sun-java5Ubuntuupstream*
Sun-java6Ubuntuhardy*
Sun-java6Ubuntuintrepid*
Sun-java6Ubuntujaunty*
Sun-java6Ubuntukarmic*
Sun-java6Ubuntulucid*
Sun-java6Ubuntuupstream*

References