[Forgot Password]
Login  Register Subscribe

23631

 
 

122183

 
 

98060

 
 

909

 
 

79198

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2009-3873

Date: (C)2009-11-05   (M)2017-11-18 


The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.

CVSS Score: 9.3Access Vector: NETWORK
Exploit Score: 8.6Access Complexity: MEDIUM
Impact Score: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE





Reference:
SECTRACK-1023132
SUNALERT-270474
BID-36881
SECUNIA-37231
SECUNIA-37239
SECUNIA-37386
SECUNIA-37581
SECUNIA-37841
ADV-2009-3131
APPLE-SA-2009-12-03-1
APPLE-SA-2009-12-03-2
GLSA-200911-02
HPSBMU02703
HPSBMU02799
MDVSA-2010:084
RHSA-2009:1694
SSRT100019
SSRT100242
SUSE-SA:2009:058
http://java.sun.com/javase/6/webnotes/6u17.html
http://support.apple.com/kb/HT3969
http://support.apple.com/kb/HT3970
http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html

CPE    127
cpe:/a:sun:jdk:1.6.0:update_2
cpe:/a:sun:jre:1.3.1_25
cpe:/a:sun:sdk:1.3.1_25
cpe:/a:sun:sdk:1.4.2_04
...
CWE    1
CWE-119
OVAL    10
oval:org.secpod.oval:def:400070
oval:org.secpod.oval:def:19728
oval:org.secpod.oval:def:101974
oval:org.secpod.oval:def:202085
...

© 2013 SecPod Technologies