TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2009-2675

N/A

Beschreibung

Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.

CVE Details

CVSS v3.1 BewertungN/A
Veroffentlicht8/5/2009
Zuletzt geandert4/23/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

sun:jdksun:jre

Schwachen (CWE)

CWE-264

Referenzen

http://marc.info/?l=bugtraq&m=125787273209737&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/36162(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/36176(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/36180(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/36199(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/36248(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/37300(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/37386(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/37460(af854a3a-2127-422b-91ae-364da2661108)
http://security.gentoo.org/glsa/glsa-200911-02.xml(af854a3a-2127-422b-91ae-364da2661108)
http://www.us-cert.gov/cas/techalerts/TA09-294A.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2009/2543(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2009/3316(af854a3a-2127-422b-91ae-364da2661108)
http://www.zerodayinitiative.com/advisories/ZDI-09-049/(af854a3a-2127-422b-91ae-364da2661108)
https://rhn.redhat.com/errata/RHSA-2009-1199.html(af854a3a-2127-422b-91ae-364da2661108)
https://rhn.redhat.com/errata/RHSA-2009-1200.html(af854a3a-2127-422b-91ae-364da2661108)
https://rhn.redhat.com/errata/RHSA-2009-1201.html(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.